7.8
/ 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
In the Linux kernel, the following vulnerability has been resolved:
nfc: rawsock: cancel tx_work before socket teardown
In rawsock_release(), cancel any pending tx_work and purge the write
queue before orphaning the socket. rawsock_tx_work runs on the system
workqueue and calls nfc_data_exchange which dereferences the NCI
device. Without synchronization, tx_work can race with socket and
device teardown when a process is killed (e.g. by SIGKILL), leading
to use-after-free or leaked references.
Set SEND_SHUTDOWN first so that if tx_work is already running it will
see the flag and skip transmitting, then use cancel_work_sync to wait
for any in-progress execution to finish, and finally purge any
remaining queued skbs.
nfc: rawsock: cancel tx_work before socket teardown
In rawsock_release(), cancel any pending tx_work and purge the write
queue before orphaning the socket. rawsock_tx_work runs on the system
workqueue and calls nfc_data_exchange which dereferences the NCI
device. Without synchronization, tx_work can race with socket and
device teardown when a process is killed (e.g. by SIGKILL), leading
to use-after-free or leaked references.
Set SEND_SHUTDOWN first so that if tx_work is already running it will
see the flag and skip transmitting, then use cancel_work_sync to wait
for any in-progress execution to finish, and finally purge any
remaining queued skbs.
Basic Information
ID
CVE-2026-23372
Source
Linux
Published
Mar 25, 2026 at 10:27
Modified
Apr 2, 2026 at 14:44
Affected Product
Vendor
Linux
Product
Linux
Version
23b7869c0fd08d73c9f83a2db88a13312d6198bb
Affected Versions
Linux Linux 23b7869c0fd08d73c9f83a2db88a13312d6198bb
Linux Linux 23b7869c0fd08d73c9f83a2db88a13312d6198bb
Linux Linux 23b7869c0fd08d73c9f83a2db88a13312d6198bb
Linux Linux 23b7869c0fd08d73c9f83a2db88a13312d6198bb
Linux Linux 23b7869c0fd08d73c9f83a2db88a13312d6198bb
Linux Linux 23b7869c0fd08d73c9f83a2db88a13312d6198bb
Linux Linux 3.1
Linux Linux 23b7869c0fd08d73c9f83a2db88a13312d6198bb
Linux Linux 23b7869c0fd08d73c9f83a2db88a13312d6198bb
Linux Linux 23b7869c0fd08d73c9f83a2db88a13312d6198bb
Linux Linux 23b7869c0fd08d73c9f83a2db88a13312d6198bb
Linux Linux 23b7869c0fd08d73c9f83a2db88a13312d6198bb
Linux Linux 3.1
References
- git.kernel.org /stable/c/3ae592ed91bb4b6b51df256b51045c13d2656049
- git.kernel.org /stable/c/722a28b635ec281bb08a23885223526d8e7d6526
- git.kernel.org /stable/c/78141b8832e16d80d09cbefb4258612db0777a24
- git.kernel.org /stable/c/edc988613def90c5b558e025b1b423f48007be06
- git.kernel.org /stable/c/da4515fc8263c5933ed605e396af91079806dc45
- git.kernel.org /stable/c/d793458c45df2aed498d7f74145eab7ee22d25aa