Answer in brief
CVE-2026-90224 records a Unknown severity vulnerability in nfc: nci: fix double completion race in nci_data_exchange_complete. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=7ed00a3edc8597fe2333f524401e2889aa1b5edf <3f075832734005310740d148d1cf1c1e792ebdca || >=5eef9ebec7f5738f12cadede3545c05b34bf5ac3 <588ccd19a6e69eca72d54608c3ab3b45709b2305 || >=ca54e904a071aa65ef3ad46ba42d51aaac6b73b4 <cf646a9f5554bc07d6ccb59c327812b3a0c6a368 || >=eb435d150ca74b4d40f77f1a2266f3636ed64a79 <9030a1bbe2c6b1e3e54cef462d159b5248f09fd2 || >=1edc12d2bbcb7a8d0f1088e6fccb9d8c01bb1289 <bfdf412208fea7fc0d5b32d68a35b25261917393 || >=d89b74bf08f067b55c03d7f999ba0a0e73177eb3 <ba4c776af3dc21ed04e315e6545e99703bb1b53a || >=4527025d440ce84bf56e75ce1df2e84cb8178616 <ee08414d78b851e3d1856d6e4d631939b01a1bbe || >=4527025d440ce84bf56e75ce1df2e84cb8178616 <8265a626cc14a48e46e6dc8c47667e72b4232ac2 || 09143c0e8f3b03517e6233aad42f45c794d8df8e || >=5.10.253 <5.10.270 || >=5.15.203 <5.15.221 || >=6.1.168 <6.1.188 || >=6.6.131 <6.6.157 || >=6.12.80 <6.12.110 || >=6.18.21 <6.18.52 || >=6.19.11 <6.20 | 3f075832734005310740d148d1cf1c1e792ebdca, 588ccd19a6e69eca72d54608c3ab3b45709b2305, cf646a9f5554bc07d6ccb59c327812b3a0c6a368, 9030a1bbe2c6b1e3e54cef462d159b5248f09fd2, bfdf412208fea7fc0d5b32d68a35b25261917393, ba4c776af3dc21ed04e315e6545e99703bb1b53a, ee08414d78b851e3d1856d6e4d631939b01a1bbe, 8265a626cc14a48e46e6dc8c47667e72b4232ac2, 5.10.270, 5.15.221, 6.1.188, 6.6.157, 6.12.110, 6.18.52, 6.20 |
| Linux/Linuxgeneric | 7.0 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix double completion race in nci_data_exchange_complete nci_close_device() and nci_rx_work can both call nci_data_exchange_complete() concurrently. After commit 4527025d440ce8 ("nfc: nci: fix circular locking dependency in nci_close_device") moved flush_workqueue(ndev->rx_wq) after mutex_unlock(&ndev->req_lock), rx_work is no longer serialized with the explicit completion call in the close path. Both callers read the non-NULL callback pointer and invoke rawsock_data_exchange_complete(), which calls sock_put() -- but only one sock_hold() was taken, so the second sock_put() underflows the refcount and frees the socket while it is still in use. Replace the bare clear_bit(NCI_DATA_EXCHANGE) with test_and_clear_bit() so that only the first caller proceeds to invoke the callback.
Quoted source text, attributed separately from HOL analysis.