CVE 7.8 HIGH

nfc: rawsock: cancel tx_work before socket teardown_CVE-2026-23372

7.8 / 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

In the Linux kernel, the following vulnerability has been resolved:

nfc: rawsock: cancel tx_work before socket teardown

In rawsock_release(), cancel any pending tx_work and purge the write
queue before orphaning the socket. rawsock_tx_work runs on the system
workqueue and calls nfc_data_exchange which dereferences the NCI
device. Without synchronization, tx_work can race with socket and
device teardown when a process is killed (e.g. by SIGKILL), leading
to use-after-free or leaked references.

Set SEND_SHUTDOWN first so that if tx_work is already running it will
see the flag and skip transmitting, then use cancel_work_sync to wait
for any in-progress execution to finish, and finally purge any
remaining queued skbs.

Basic Information

ID CVE-2026-23372
Source Linux
Published Mar 25, 2026 at 10:27
Modified Apr 2, 2026 at 14:44

Affected Product

Vendor Linux
Product Linux
Version 23b7869c0fd08d73c9f83a2db88a13312d6198bb
Affected Versions Linux Linux 23b7869c0fd08d73c9f83a2db88a13312d6198bb
Linux Linux 23b7869c0fd08d73c9f83a2db88a13312d6198bb
Linux Linux 23b7869c0fd08d73c9f83a2db88a13312d6198bb
Linux Linux 23b7869c0fd08d73c9f83a2db88a13312d6198bb
Linux Linux 23b7869c0fd08d73c9f83a2db88a13312d6198bb
Linux Linux 23b7869c0fd08d73c9f83a2db88a13312d6198bb
Linux Linux 3.1

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.