CVE-2026-90225
Received
Received - Intake
BaseFortify
Vulnerability report for CVE-2026-90225, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-17
Last updated on: 2026-09-18
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
nfc: llcp: read llcp_sock->local under the socket lock in getsockopt
nfc_llcp_getsockopt() read llcp_sock->local before lock_sock(sk) and
then dereferenced the cached pointer inside the locked region.
llcp_sock_bind() assigns and clears llcp_sock->local under the same
socket lock, dropping the last reference on its error path. A
getsockopt() racing an in-flight bind() can observe the pointer, block
on lock_sock(), and then dereference a freed nfc_llcp_local once bind()
has unwound.
Move the llcp_sock->local read and the NULL check inside the
lock_sock(sk) region so bind() cannot mutate or free the pointer between
the load and the use.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | 26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 |
| Linux | Linux | 26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 |
| Linux | Linux | 26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 |
| Linux | Linux | 26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 |
| Linux | Linux | 26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 |
| Linux | Linux | 26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 |
| Linux | Linux | 26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 |
| Linux | Linux | 26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 |
| Linux | Linux | 3.10 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |