CVE-2026-31629
published 2026-04-24CVE-2026-31629: In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: add missing return after LLCP_CLOSED checks In nfc_llcp_recv_hdlc() and…
PriorityP345high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
0.22%
12.9th percentile
In the Linux kernel, the following vulnerability has been resolved:
nfc: llcp: add missing return after LLCP_CLOSED checks
In nfc_llcp_recv_hdlc() and nfc_llcp_recv_disc(), when the socket
state is LLCP_CLOSED, the code correctly calls release_sock() and
nfc_llcp_sock_put() but fails to return. Execution falls through to
the remainder of the function, which calls release_sock() and
nfc_llcp_sock_put() again. This results in a double release_sock()
and a refcount underflow via double nfc_llcp_sock_put(), leading to
a use-after-free.
Add the missing return statements after the LLCP_CLOSED branches
in both functions to prevent the fall-through.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux | — | — |
| linux | linux | >= d646960f7986fefb460a2b062d5ccc8ccfeacc3a < b2a23529593d011fb433a3d711fc597ed6a6bd2f | b2a23529593d011fb433a3d711fc597ed6a6bd2f |
| linux | linux | >= d646960f7986fefb460a2b062d5ccc8ccfeacc3a < 665315df9c3486cb213fc44d83cc8bcd47fe0d26 | 665315df9c3486cb213fc44d83cc8bcd47fe0d26 |
| linux | linux | >= d646960f7986fefb460a2b062d5ccc8ccfeacc3a < 9b49e2a4b8219a2fc5cebf94f4ec34e509aff8a6 | 9b49e2a4b8219a2fc5cebf94f4ec34e509aff8a6 |
| linux | linux | >= d646960f7986fefb460a2b062d5ccc8ccfeacc3a < 0eb1263a3b8c36418c9ba295c9ab3abed664edbf | 0eb1263a3b8c36418c9ba295c9ab3abed664edbf |
| linux | linux | >= d646960f7986fefb460a2b062d5ccc8ccfeacc3a < 796e0cac058252d0ad34ebe288e6f7979b5fc9b2 | 796e0cac058252d0ad34ebe288e6f7979b5fc9b2 |
| linux | linux | >= d646960f7986fefb460a2b062d5ccc8ccfeacc3a < 8977fad2b3c6eefd414131168d597c5d1d5e1abf | 8977fad2b3c6eefd414131168d597c5d1d5e1abf |
| linux | linux | >= d646960f7986fefb460a2b062d5ccc8ccfeacc3a < ff3d9e8f7244293e303f7b6ef70774291c7c27e9 | ff3d9e8f7244293e303f7b6ef70774291c7c27e9 |
| linux | linux | >= d646960f7986fefb460a2b062d5ccc8ccfeacc3a < aba4712e8f0381cd5d196534ce2ad082626a5ab6 | aba4712e8f0381cd5d196534ce2ad082626a5ab6 |
| linux | linux | >= d646960f7986fefb460a2b062d5ccc8ccfeacc3a < 2b5dd4632966c39da6ba74dbc8689b309065e82c | 2b5dd4632966c39da6ba74dbc8689b309065e82c |
| linux | linux_kernel | >= 3.3 < 6.6.136 | 6.6.136 |
| linux | linux_kernel | >= 6.13 < 6.18.24 | 6.18.24 |
| linux | linux_kernel | >= 6.19 < 6.19.14 | 6.19.14 |
| linux | linux_kernel | >= 6.7 < 6.12.83 | 6.12.83 |
| linux | linux_kernel | >= 7.0 < 7.0.1 | 7.0.1 |
| ubuntu | linux | — | — |
| ubuntu | linux-aws | — | — |
| ubuntu | linux-gcp | — | — |
| ubuntu | linux-ibm | — | — |
| ubuntu | linux-nvidia | — | — |
| ubuntu | linux-oracle | — | — |
| ubuntu | linux-raspi | — | — |
| ubuntu | linux-realtime | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu2.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (NVIDIA) vulnerabilities
vendor_ubuntu·2026-07-06·CVSS 2.0
CVE-2026-46009 [LOW] Linux kernel (NVIDIA) vulnerabilities
Title: Linux kernel (NVIDIA) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- x86 architecture;
- Block layer subsystem;
- Cryptographic API;
- Rados block device (RBD) driver;
- Compressed RAM block device driver;
- Character device driver;
- TPM device driver;
- Hardware crypto device drivers;
- EDAC drivers;
- GPU drivers;
- Greybus drive
Ubuntu
Linux kernel (Raspberry Pi) vulnerabilities
vendor_ubuntu·2026-07-02·CVSS 2.0
CVE-2026-46316 [LOW] Linux kernel (Raspberry Pi) vulnerabilities
Title: Linux kernel (Raspberry Pi) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- x86 architecture;
- Block layer subsystem;
- Cryptographic API;
- Rados block device (RBD) driver;
- Compressed RAM block device driver;
- Character device driver;
- TPM device driver;
- Hardware crypto device drivers;
- EDAC drivers;
- GPU drivers;
- Greybus
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2026-07-01·CVSS 2.0
CVE-2026-46042 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that some AMD processors did not properly clear data in
the floating point divider unit during speculative execution. A local
attacker could use this to expose sensitive information. (CVE-2025-54505)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- x86 architecture;
- Block layer subsystem;
- Cryptographic API;
- Rados block device (RBD) driver;
- Compressed RAM block device driver;
- Character device driver;
- TPM device driver;
- Hardware crypto device drivers;
- EDAC drivers;
- GPU drivers;
- Greybus drivers;
- HID
Red Hat
kernel: nfc: llcp: add missing return after LLCP_CLOSED checks
vendor_redhat·2026-04-24
CVE-2026-31629 CWE-911 kernel: nfc: llcp: add missing return after LLCP_CLOSED checks
kernel: nfc: llcp: add missing return after LLCP_CLOSED checks
A flaw was found in the Linux kernel's Near Field Communication (NFC) Logical Link Control Protocol (LLCP) subsystem. Missing return statements after LLCP_CLOSED checks in the nfc_llcp_recv_hdlc() and nfc_llcp_recv_disc() functions can lead to a use-after-free vulnerability. This occurs because the system attempts to release resources twice, causing a reference count underflow. An attacker could potentially exploit this to cause a denial of service or other system instability.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Packa
GHSA
GHSA-cfpg-q83x-6923: In the Linux kernel, the following vulnerability has been resolved:
nfc: llcp: add missing return after LLCP_CLOSED checks
In nfc_llcp_recv_hdlc() a
ghsa_unreviewed·2026-04-24
CVE-2026-31629 GHSA-cfpg-q83x-6923: In the Linux kernel, the following vulnerability has been resolved:
nfc: llcp: add missing return after LLCP_CLOSED checks
In nfc_llcp_recv_hdlc() a
In the Linux kernel, the following vulnerability has been resolved:
nfc: llcp: add missing return after LLCP_CLOSED checks
In nfc_llcp_recv_hdlc() and nfc_llcp_recv_disc(), when the socket
state is LLCP_CLOSED, the code correctly calls release_sock() and
nfc_llcp_sock_put() but fails to return. Execution falls through to
the remainder of the function, which calls release_sock() and
nfc_llcp_sock_put() again. This results in a double release_sock()
and a refcount underflow via double nfc_llcp_sock_put(), leading to
a use-after-free.
Add the missing return statements after the LLCP_CLOSED branches
in both functions to prevent the fall-through.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/0eb1263a3b8c36418c9ba295c9ab3abed664edbfhttps://git.kernel.org/stable/c/2b5dd4632966c39da6ba74dbc8689b309065e82chttps://git.kernel.org/stable/c/665315df9c3486cb213fc44d83cc8bcd47fe0d26https://git.kernel.org/stable/c/796e0cac058252d0ad34ebe288e6f7979b5fc9b2https://git.kernel.org/stable/c/8977fad2b3c6eefd414131168d597c5d1d5e1abfhttps://git.kernel.org/stable/c/9b49e2a4b8219a2fc5cebf94f4ec34e509aff8a6https://git.kernel.org/stable/c/aba4712e8f0381cd5d196534ce2ad082626a5ab6https://git.kernel.org/stable/c/b2a23529593d011fb433a3d711fc597ed6a6bd2fhttps://git.kernel.org/stable/c/ff3d9e8f7244293e303f7b6ef70774291c7c27e9
2026-04-24
Published