In the Linux kernel, the following vulnerability has been resolved:
nfc: rawsock: cancel tx_work before socket teardown
In rawsock_release(), cancel any pending tx_work and purge the write
queue before orphaning the socket. rawsock_tx_work runs on the system
workqueue and calls nfc_data_exchange which dereferences the NCI
device. Without synchronization, tx_work can race with socket and
device teardown when a process is killed (e.g. by SIGKILL), leading
to use-after-free or leaked references.
Set SEND_SHUTDOWN first so that if tx_work is already running it will
see the flag and skip transmitting, then use cancel_work_sync to wait
for any in-progress execution to finish, and finally purge any
remaining queued skbs.
References
Configurations
Configuration 1 (hide)
|
History
24 Apr 2026, 16:36
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://git.kernel.org/stable/c/3ae592ed91bb4b6b51df256b51045c13d2656049 - Patch | |
| References | () https://git.kernel.org/stable/c/722a28b635ec281bb08a23885223526d8e7d6526 - Patch | |
| References | () https://git.kernel.org/stable/c/78141b8832e16d80d09cbefb4258612db0777a24 - Patch | |
| References | () https://git.kernel.org/stable/c/9b2d23cd09e1cb56bdf0e4d5614703094159f16c - Patch | |
| References | () https://git.kernel.org/stable/c/cdeed45ce8c92defd057f7d67ee9a69374d8fa16 - Patch | |
| References | () https://git.kernel.org/stable/c/d793458c45df2aed498d7f74145eab7ee22d25aa - Patch | |
| References | () https://git.kernel.org/stable/c/da4515fc8263c5933ed605e396af91079806dc45 - Patch | |
| References | () https://git.kernel.org/stable/c/edc988613def90c5b558e025b1b423f48007be06 - Patch | |
| CWE | NVD-CWE-noinfo | |
| CPE | cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:3.1:-:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:* |
|
| First Time |
Linux
Linux linux Kernel |
18 Apr 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
02 Apr 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
| Summary |
|
25 Mar 2026, 11:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-25 11:16
Updated : 2026-04-24 16:36
NVD link : CVE-2026-23372
Mitre link : CVE-2026-23372
CVE.ORG link : CVE-2026-23372
JSON object : View
Products Affected
linux
- linux_kernel
CWE
