CVE-2026-90225
CVE CVE-2026-90225EUVD EUVD-2026-81818Published 2026-09-17T16:07:34.000ZLast changed 2026-09-18T17:53:52.000ZCVSS 7.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: read llcp_sock->local under the socket lock in getsockopt nfc_llcp_getsockopt() read llcp_sock->local before lock_sock(sk) and then dereferenced the cached pointer inside the locked region. llcp_sock_bind() assigns and clears llcp_sock->local under the same socket lock, dropping the last reference on its error path. A getsockopt() racing an in-flight bind() can observe the pointer, block on lock_sock(), and then dereference a freed nfc_llcp_local once bind() has unwound. Move the llcp_sock->local read and the NULL check inside the lock_sock(sk) region so bind() cannot mutate or free the pointer between the load and the use.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 <56fd158fef20268f48db6cdfe5d722e930134eda; patch: 6.6.157; 26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 <36812527052c5bfb1ec6c1e292d67a5bf76b750f; patch: 6.18.52; 26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 <ed5240bab3468988077fe8bf29b935eaecc9ff89; patch: 0; patch: 5.15.221; patch: 6.12.110; 26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 <8ba8cec0586727cc135ca4827921fc7b52946d71; 26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 <156e65bd29307f5053835bff60bc1ba342fa010f; 26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 <fe65727a4a21b11c18eebae1338482767a897b76; 3.10; patch: 7.3-rc1; patch: 5.10.270; 26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 <2d8ac24565be85bf56580b87bf1b874d35625eb5; patch: 7.2.6; patch: 6.1.188; 26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 <d1b73962675cdc5a58e2707e25b548d8b495fde0
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.