Use-After-Free Vulnerability in Linux Kernel's NFC Functionality
CVE-2026-64011
What is CVE-2026-64011?
A use-after-free vulnerability has been identified in the NFC protocol implementation within the Linux kernel. The issue arises during the execution of the llcp_sock_release() function, which incorrectly handles the unlinking of sockets. Specifically, if a socket is still in a connecting state, it remains on the connecting list and may lead to potential exploit scenarios. This vulnerability has been addressed to ensure that the socket state is verified before unlinking, thereby enhancing the security of the NFC subsystem and mitigating risks associated with improper memory management.
Affected Version(s)
Linux b4011239a08e7e6c2c6e970dfa9e8ecb73139261 < 89ba026747019ee643d29407435ddc118e6ca908
Linux b4011239a08e7e6c2c6e970dfa9e8ecb73139261
Linux b4011239a08e7e6c2c6e970dfa9e8ecb73139261 < 2dfdaaf7d933b676124aadec6698825e95f94fe9