CVE-2026-90224
HighIn the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix double completion race in nci_data_exchange_complete nci_close_device() and nci_rx_work can both call nci_data_exchange_complete() concurrently. After commit 4527025d440ce8 ("nfc: nci: fix circular locking dependency in nci_close_device") moved flush_workqueue(ndev->rx_wq) after mutex_unlock(&ndev->req_lock), rx_work is no longer serialized with the explicit completion call in the close path. Both callers read the non-NULL callback pointer and invoke rawsock_data_exchange_complete(), which calls sock_put() -- but only one sock_hold() was taken, so the second sock_put() underflows the refcount and frees the socket while it is still in use. Replace the bare clear_bit(NCI_DATA_EXCHANGE) with test_and_clear_bit() so that only the first caller proceeds to invoke the callback.
CVSS 3.1 score
7.5
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected versions
Linux kernel versions
5.10.253,
5.15.203,
6.1.168,
6.6.131,
6.12.80,
6.18.21,
6.19.11,
7.0
and later are affected. Fixed in
5.10.270,
5.15.221,
6.1.188,
6.6.157,
6.12.110,
6.18.52,
7.2.6,
7.3-rc1
and their respective stable series.
References
8 totalFrequently asked questions
-
What is CVE-2026-90224?
CVE-2026-90224 is a High severity Linux kernel vulnerability with a CVSS score of 7.5 out of 10 . It affects Linux kernel versions from 5.10.253 onward and has been patched in 5.10.270, 5.15.221, 6.1.188 and others. CVE-2026-90224 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
What is the CVSS score for CVE-2026-90224?
CVE-2026-90224 has a CVSS score of 7.5 out of 10, rated High severity (CVSS 3.1). The vector string is
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. -
Is there a patch available for CVE-2026-90224?
Yes. CVE-2026-90224 has been patched. Fixed versions include 5.10.270, 5.15.221, 6.1.188 and others. If you are running Linux kernel 5.10.253 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2026-90224 actively exploited?
No. CVE-2026-90224 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.