« Volver al listado

CVE-2026-90224

Estado: RecibidaAlta (7.5)—

In the Linux kernel, the following vulnerability has been resolved:

nfc: nci: fix double completion race in nci_data_exchange_complete

nci_close_device() and nci_rx_work can both call nci_data_exchange_complete() concurrently. After commit 4527025d440ce8 ("nfc: nci: fix circular locking dependency in nci_close_device") moved flush_workqueue(ndev->rx_wq) after mutex_unlock(&ndev->req_lock), rx_work is no longer serialized with the explicit completion call in the close path. Both callers read the non-NULL callback pointer and invoke rawsock_data_exchange_complete(), which calls sock_put() -- but only one sock_hold() was taken, so the second sock_put() underflows the refcount and frees the socket while it is still in use.

Leer descripción completaMostrar menos

Replace the bare clear_bit(NCI_DATA_EXCHANGE) with test_and_clear_bit() so that only the first caller proceeds to invoke the callback.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:A sugiere explotación de servicio NFC/red adyacente (T1210). Race condition causa DoS por desbordamiento de refcount y liberación prematura de socket; potencial corrupción de memoria (T1499.004). Confianza moderada: no hay CVE de NFC con explotación documentada.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90224",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.6
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7ed00a3edc8597fe2333f524401e2889aa1b5edf",
              "lessThan": "3f075832734005310740d148d1cf1c1e792ebdca",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5eef9ebec7f5738f12cadede3545c05b34bf5ac3",
              "lessThan": "588ccd19a6e69eca72d54608c3ab3b45709b2305",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ca54e904a071aa65ef3ad46ba42d51aaac6b73b4",
              "lessThan": "cf646a9f5554bc07d6ccb59c327812b3a0c6a368",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "eb435d150ca74b4d40f77f1a2266f3636ed64a79",
              "lessThan": "9030a1bbe2c6b1e3e54cef462d159b5248f09fd2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "1edc12d2bbcb7a8d0f1088e6fccb9d8c01bb1289",
              "lessThan": "bfdf412208fea7fc0d5b32d68a35b25261917393",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d89b74bf08f067b55c03d7f999ba0a0e73177eb3",
              "lessThan": "ba4c776af3dc21ed04e315e6545e99703bb1b53a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4527025d440ce84bf56e75ce1df2e84cb8178616",
              "lessThan": "ee08414d78b851e3d1856d6e4d631939b01a1bbe",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4527025d440ce84bf56e75ce1df2e84cb8178616",
              "lessThan": "8265a626cc14a48e46e6dc8c47667e72b4232ac2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "09143c0e8f3b03517e6233aad42f45c794d8df8e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.10.253",
              "lessThan": "5.10.270",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.15.203",
              "lessThan": "5.15.221",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.1.168",
              "lessThan": "6.1.188",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.6.131",
              "lessThan": "6.6.157",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.12.80",
              "lessThan": "6.12.110",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.18.21",
              "lessThan": "6.18.52",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.19.11",
              "lessThan": "6.20",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "net/nfc/nci/data.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.270",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/nfc/nci/data.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:17.997",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/3f075832734005310740d148d1cf1c1e792ebdca",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/588ccd19a6e69eca72d54608c3ab3b45709b2305",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8265a626cc14a48e46e6dc8c47667e72b4232ac2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/9030a1bbe2c6b1e3e54cef462d159b5248f09fd2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ba4c776af3dc21ed04e315e6545e99703bb1b53a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bfdf412208fea7fc0d5b32d68a35b25261917393",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cf646a9f5554bc07d6ccb59c327812b3a0c6a368",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ee08414d78b851e3d1856d6e4d631939b01a1bbe",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: nci: fix double completion race in nci_data_exchange_complete\n\nnci_close_device() and nci_rx_work can both call\nnci_data_exchange_complete() concurrently.  After commit 4527025d440ce8\n(\"nfc: nci: fix circular locking dependency in nci_close_device\") moved\nflush_workqueue(ndev->rx_wq) after mutex_unlock(&ndev->req_lock),\nrx_work is no longer serialized with the explicit completion call in the\nclose path.  Both callers read the non-NULL callback pointer and invoke\nrawsock_data_exchange_complete(), which calls sock_put() -- but only one\nsock_hold() was taken, so the second sock_put() underflows the refcount\nand frees the socket while it is still in use.\n\nReplace the bare clear_bit(NCI_DATA_EXCHANGE) with\ntest_and_clear_bit() so that only the first caller proceeds to invoke\nthe callback."
    }
  ],
  "lastModified": "2026-09-18T18:17:47.140",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}