CVE-2026-31629 (GCVE-0-2026-31629)
Vulnerability from cvelistv5
Published
2026-04-24 14:42
Modified
2026-08-05 12:23
Summary
In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: add missing return after LLCP_CLOSED checks In nfc_llcp_recv_hdlc() and nfc_llcp_recv_disc(), when the socket state is LLCP_CLOSED, the code correctly calls release_sock() and nfc_llcp_sock_put() but fails to return. Execution falls through to the remainder of the function, which calls release_sock() and nfc_llcp_sock_put() again. This results in a double release_sock() and a refcount underflow via double nfc_llcp_sock_put(), leading to a use-after-free. Add the missing return statements after the LLCP_CLOSED branches in both functions to prevent the fall-through.
Impacted products
Vendor Product Version
Linux Linux Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a
Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a
Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a
Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a
Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a
Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a
Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a
Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a
Version: d646960f7986fefb460a2b062d5ccc8ccfeacc3a
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "net/nfc/llcp_core.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "b2a23529593d011fb433a3d711fc597ed6a6bd2f",
              "status": "affected",
              "version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
              "versionType": "git"
            },
            {
              "lessThan": "665315df9c3486cb213fc44d83cc8bcd47fe0d26",
              "status": "affected",
              "version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
              "versionType": "git"
            },
            {
              "lessThan": "9b49e2a4b8219a2fc5cebf94f4ec34e509aff8a6",
              "status": "affected",
              "version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
              "versionType": "git"
            },
            {
              "lessThan": "0eb1263a3b8c36418c9ba295c9ab3abed664edbf",
              "status": "affected",
              "version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
              "versionType": "git"
            },
            {
              "lessThan": "796e0cac058252d0ad34ebe288e6f7979b5fc9b2",
              "status": "affected",
              "version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
              "versionType": "git"
            },
            {
              "lessThan": "8977fad2b3c6eefd414131168d597c5d1d5e1abf",
              "status": "affected",
              "version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
              "versionType": "git"
            },
            {
              "lessThan": "ff3d9e8f7244293e303f7b6ef70774291c7c27e9",
              "status": "affected",
              "version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
              "versionType": "git"
            },
            {
              "lessThan": "aba4712e8f0381cd5d196534ce2ad082626a5ab6",
              "status": "affected",
              "version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
              "versionType": "git"
            },
            {
              "lessThan": "2b5dd4632966c39da6ba74dbc8689b309065e82c",
              "status": "affected",
              "version": "d646960f7986fefb460a2b062d5ccc8ccfeacc3a",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "net/nfc/llcp_core.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.3"
            },
            {
              "lessThan": "3.3",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.258",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.209",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.175",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.136",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.83",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.24",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.19.*",
              "status": "unaffected",
              "version": "6.19.14",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.0.*",
              "status": "unaffected",
              "version": "7.0.1",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.1",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.258",
                  "versionStartIncluding": "3.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.209",
                  "versionStartIncluding": "3.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.175",
                  "versionStartIncluding": "3.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.136",
                  "versionStartIncluding": "3.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.83",
                  "versionStartIncluding": "3.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.24",
                  "versionStartIncluding": "3.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.19.14",
                  "versionStartIncluding": "3.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.0.1",
                  "versionStartIncluding": "3.3",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.1",
                  "versionStartIncluding": "3.3",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: llcp: add missing return after LLCP_CLOSED checks\n\nIn nfc_llcp_recv_hdlc() and nfc_llcp_recv_disc(), when the socket\nstate is LLCP_CLOSED, the code correctly calls release_sock() and\nnfc_llcp_sock_put() but fails to return. Execution falls through to\nthe remainder of the function, which calls release_sock() and\nnfc_llcp_sock_put() again. This results in a double release_sock()\nand a refcount underflow via double nfc_llcp_sock_put(), leading to\na use-after-free.\n\nAdd the missing return statements after the LLCP_CLOSED branches\nin both functions to prevent the fall-through."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:A - The vulnerable LLCP receive handlers process NFC DEP/LLCP PDUs supplied by a nearby NFC peer over the NFC radio link. The attacker must be in NFC range, so this is adjacent rather than local or internet-routable network access.\nAC:L - The attacker can drive the required LLCP packet sequence, for example closing a matched LLCP socket with a remote control PDU and then sending DISC or I/RR/RNR for the same SAP pair. No uncontrollable race or special memory layout condition is required to trigger the double put/unlock path.\nPR:N - The triggering input is unauthenticated NFC LLCP traffic from the peer and does not require an account or privileges on the victim. Any local NFC setup or listening service is an environmental prerequisite, not a privilege held by the attacker.\nUI:N - After the victim NFC subsystem/link is active and the attacker is in range, malicious LLCP frames are processed by the kernel receive path without further victim action. Proximity is already captured by AV:A.\nS:U - The vulnerability corrupts kernel socket lifetime state within the same kernel security authority. It does not cross a VM, hypervisor, IOMMU, or separate authorization boundary.\nC:H - The bug causes a refcount imbalance and use-after-free of an NFC LLCP socket object. Kernel UAFs are defensibly treated as enabling memory disclosure primitives under the required high-severity guidance.\nI:H - The freed socket object can potentially be reclaimed and controlled, turning the UAF into kernel memory corruption or control-flow/data-structure modification. Under the required guidance, UAF impact is high for integrity.\nA:H - The double release and double sock_put can produce refcount underflow, use-after-free, warnings, oopses, or crashes in kernel socket handling. A kernel crash or panic is high availability impact."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:23:55.426Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/b2a23529593d011fb433a3d711fc597ed6a6bd2f"
        },
        {
          "url": "https://git.kernel.org/stable/c/665315df9c3486cb213fc44d83cc8bcd47fe0d26"
        },
        {
          "url": "https://git.kernel.org/stable/c/9b49e2a4b8219a2fc5cebf94f4ec34e509aff8a6"
        },
        {
          "url": "https://git.kernel.org/stable/c/0eb1263a3b8c36418c9ba295c9ab3abed664edbf"
        },
        {
          "url": "https://git.kernel.org/stable/c/796e0cac058252d0ad34ebe288e6f7979b5fc9b2"
        },
        {
          "url": "https://git.kernel.org/stable/c/8977fad2b3c6eefd414131168d597c5d1d5e1abf"
        },
        {
          "url": "https://git.kernel.org/stable/c/ff3d9e8f7244293e303f7b6ef70774291c7c27e9"
        },
        {
          "url": "https://git.kernel.org/stable/c/aba4712e8f0381cd5d196534ce2ad082626a5ab6"
        },
        {
          "url": "https://git.kernel.org/stable/c/2b5dd4632966c39da6ba74dbc8689b309065e82c"
        }
      ],
      "title": "nfc: llcp: add missing return after LLCP_CLOSED checks",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-31629",
    "datePublished": "2026-04-24T14:42:49.849Z",
    "dateReserved": "2026-03-09T15:48:24.124Z",
    "dateUpdated": "2026-08-05T12:23:55.426Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…