cbcvebase.
CVE-2026-31629
published 2026-04-24

CVE-2026-31629: In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: add missing return after LLCP_CLOSED checks In nfc_llcp_recv_hdlc() and…

PriorityP345high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
0.22%
12.9th percentile
In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: add missing return after LLCP_CLOSED checks In nfc_llcp_recv_hdlc() and nfc_llcp_recv_disc(), when the socket state is LLCP_CLOSED, the code correctly calls release_sock() and nfc_llcp_sock_put() but fails to return. Execution falls through to the remainder of the function, which calls release_sock() and nfc_llcp_sock_put() again. This results in a double release_sock() and a refcount underflow via double nfc_llcp_sock_put(), leading to a use-after-free. Add the missing return statements after the LLCP_CLOSED branches in both functions to prevent the fall-through.

Affected

23 ranges
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= d646960f7986fefb460a2b062d5ccc8ccfeacc3a < b2a23529593d011fb433a3d711fc597ed6a6bd2fb2a23529593d011fb433a3d711fc597ed6a6bd2f
linuxlinux>= d646960f7986fefb460a2b062d5ccc8ccfeacc3a < 665315df9c3486cb213fc44d83cc8bcd47fe0d26665315df9c3486cb213fc44d83cc8bcd47fe0d26
linuxlinux>= d646960f7986fefb460a2b062d5ccc8ccfeacc3a < 9b49e2a4b8219a2fc5cebf94f4ec34e509aff8a69b49e2a4b8219a2fc5cebf94f4ec34e509aff8a6
linuxlinux>= d646960f7986fefb460a2b062d5ccc8ccfeacc3a < 0eb1263a3b8c36418c9ba295c9ab3abed664edbf0eb1263a3b8c36418c9ba295c9ab3abed664edbf
linuxlinux>= d646960f7986fefb460a2b062d5ccc8ccfeacc3a < 796e0cac058252d0ad34ebe288e6f7979b5fc9b2796e0cac058252d0ad34ebe288e6f7979b5fc9b2
linuxlinux>= d646960f7986fefb460a2b062d5ccc8ccfeacc3a < 8977fad2b3c6eefd414131168d597c5d1d5e1abf8977fad2b3c6eefd414131168d597c5d1d5e1abf
linuxlinux>= d646960f7986fefb460a2b062d5ccc8ccfeacc3a < ff3d9e8f7244293e303f7b6ef70774291c7c27e9ff3d9e8f7244293e303f7b6ef70774291c7c27e9
linuxlinux>= d646960f7986fefb460a2b062d5ccc8ccfeacc3a < aba4712e8f0381cd5d196534ce2ad082626a5ab6aba4712e8f0381cd5d196534ce2ad082626a5ab6
linuxlinux>= d646960f7986fefb460a2b062d5ccc8ccfeacc3a < 2b5dd4632966c39da6ba74dbc8689b309065e82c2b5dd4632966c39da6ba74dbc8689b309065e82c
linuxlinux_kernel>= 3.3 < 6.6.1366.6.136
linuxlinux_kernel>= 6.13 < 6.18.246.18.24
linuxlinux_kernel>= 6.19 < 6.19.146.19.14
linuxlinux_kernel>= 6.7 < 6.12.836.12.83
linuxlinux_kernel>= 7.0 < 7.0.17.0.1
ubuntulinux
ubuntulinux-aws
ubuntulinux-gcp
ubuntulinux-ibm
ubuntulinux-nvidia
ubuntulinux-oracle
ubuntulinux-raspi
ubuntulinux-realtime

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu2.0LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.