Use-After-Free Vulnerability in Linux Kernel's NFC Functionality
CVE-2026-64011

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
19 July 2026

What is CVE-2026-64011?

A use-after-free vulnerability has been identified in the NFC protocol implementation within the Linux kernel. The issue arises during the execution of the llcp_sock_release() function, which incorrectly handles the unlinking of sockets. Specifically, if a socket is still in a connecting state, it remains on the connecting list and may lead to potential exploit scenarios. This vulnerability has been addressed to ensure that the socket state is verified before unlinking, thereby enhancing the security of the NFC subsystem and mitigating risks associated with improper memory management.

Affected Version(s)

Linux b4011239a08e7e6c2c6e970dfa9e8ecb73139261 < 89ba026747019ee643d29407435ddc118e6ca908

Linux b4011239a08e7e6c2c6e970dfa9e8ecb73139261

Linux b4011239a08e7e6c2c6e970dfa9e8ecb73139261 < 2dfdaaf7d933b676124aadec6698825e95f94fe9

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.