{"id":"CVE-2025-71079","title":"net: nfc: fix deadlock between nfc_unregister_device and rfkill_fop_write","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: nfc: fix deadlock between nfc_unregister_device and rfkill_fop_write\n\nA deadlock can occur between nfc_unregister_device() and rfkill_fop_write()\ndue to lock order…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 73a0d12114b4bc1a9def79a623264754b9df698e < 2e0831e9fc46a06daa6d4d8d57a2738e343130c3","Linux >= 8a9c61c3ef187d8891225f9b932390670a43a0d3 < e02a1c33f10a0ed3aba855ab8ae2b6c4c5be8012","Linux >= 3e3b5dfcd16a3e254aab61bd1e8c417dd4503102 < ee41f4f3ccf8cd6ba3732e867abbec7e6d8d12e5","Linux >= 3e3b5dfcd16a3e254aab61bd1e8c417dd4503102 < 6b93c8ab6f6cda8818983a4ae3fcf84b023037b4","Linux >= 3e3b5dfcd16a3e254aab61bd1e8c417dd4503102 < 8fc4632fb508432895430cd02b38086bdd649083","Linux >= 3e3b5dfcd16a3e254aab61bd1e8c417dd4503102 < f3a8a7c1aa278f2378b2f3a10500c6674dffdfda","Linux >= 3e3b5dfcd16a3e254aab61bd1e8c417dd4503102 < 1ab526d97a57e44d26fadcc0e9adeb9c0c0182f5","Linux 5ef16d2d172ee56714cff37cd005b98aba08ef5a","Linux ff169909eac9e00bf1aa0af739ba6ddfb1b1d135","Linux 47244ac0b65bd74cc70007d8e1bac68bd2baad19","Linux c45cea83e13699bdfd47842e04d09dd43af4c371","Linux 307d2e6cebfca9d92f86c8e2c8e3dd4a8be46ba6","Linux >= 5.10.82 < 5.10.248","Linux >= 5.15.5 < 5.15.198","Linux >= 4.4.293 < 4.5","Linux >= 4.9.291 < 4.10","Linux >= 4.14.256 < 4.15","Linux >= 4.19.218 < 4.20","Linux >= 5.4.162 < 5.5","Linux 5.16"],"published":"2026-01-13","updated":"2026-09-08","sourceUpdated":"2026-09-08T08:43:43.375Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2025-71079","references":[{"url":"https://git.kernel.org/stable/c/2e0831e9fc46a06daa6d4d8d57a2738e343130c3"},{"url":"https://git.kernel.org/stable/c/e02a1c33f10a0ed3aba855ab8ae2b6c4c5be8012"},{"url":"https://git.kernel.org/stable/c/ee41f4f3ccf8cd6ba3732e867abbec7e6d8d12e5"},{"url":"https://git.kernel.org/stable/c/6b93c8ab6f6cda8818983a4ae3fcf84b023037b4"},{"url":"https://git.kernel.org/stable/c/8fc4632fb508432895430cd02b38086bdd649083"},{"url":"https://git.kernel.org/stable/c/f3a8a7c1aa278f2378b2f3a10500c6674dffdfda"},{"url":"https://git.kernel.org/stable/c/1ab526d97a57e44d26fadcc0e9adeb9c0c0182f5"}],"tags":["cve.org"],"epss":0.00102,"epssPercentile":0.01044,"ingestedAt":"2026-09-08T15:33:26.995Z","slug":"CVE-2025-71079","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet: nfc: fix deadlock between nfc_unregister_device and rfkill_fop_write\n\nA deadlock can occur between nfc_unregister_device() and rfkill_fop_write()\ndue to lock ordering inversion between device_lock and rfkill_global_mutex.\n\nThe problematic lock order is:\n\nThread A (rfkill_fop_write):\n  rfkill_fop_write()\n    mutex_lock(&rfkill_global_mutex)\n      rfkill_set_block()\n        nfc_rfkill_set_block()\n          nfc_dev_down()\n            device_lock(&dev->dev)    <- waits for device_lock\n\nThread B (nfc_unregister_device):\n  nfc_unregister_device()\n    device_lock(&dev->dev)\n      rfkill_unregister()\n        mutex_lock(&rfkill_global_mutex)  <- waits for rfkill_global_mutex\n\nThis creates a classic ABBA deadlock scenario.\n\nFix this by moving rfkill_unregister() and rfkill_destroy() outside the\ndevice_lock critical section. Store the rfkill pointer in a local variable\nbefore releasing the lock, then call rfkill_unregister() after releasing\ndevice_lock.\n\nThis change is safe because rfkill_fop_write() holds rfkill_global_mutex\nwhile calling the rfkill callbacks, and rfkill_unregister() also acquires\nrfkill_global_mutex before cleanup. Therefore, rfkill_unregister() will\nwait for any ongoing callback to complete before proceeding, and\ndevice_del() is only called after rfkill_unregister() returns, preventing\nany use-after-free.\n\nThe similar lock ordering in nfc_register_device() (device_lock ->\nrfkill_global_mutex via rfkill_register) is safe because during\nregistration the device is not yet in rfkill_list, so no concurrent\nrfkill operations can occur on this device.\n\n## Affected\n\n- `Linux >= 73a0d12114b4bc1a9def79a623264754b9df698e < 2e0831e9fc46a06daa6d4d8d57a2738e343130c3`\n- `Linux >= 8a9c61c3ef187d8891225f9b932390670a43a0d3 < e02a1c33f10a0ed3aba855ab8ae2b6c4c5be8012`\n- `Linux >= 3e3b5dfcd16a3e254aab61bd1e8c417dd4503102 < ee41f4f3ccf8cd6ba3732e867abbec7e6d8d12e5`\n- `Linux >= 3e3b5dfcd16a3e254aab61bd1e8c417dd4503102 < 6b93c8ab6f6cda8818983a4ae3fcf84b023037b4`\n- `Linux >= 3e3b5dfcd16a3e254aab61bd1e8c417dd4503102 < 8fc4632fb508432895430cd02b38086bdd649083`\n- `Linux >= 3e3b5dfcd16a3e254aab61bd1e8c417dd4503102 < f3a8a7c1aa278f2378b2f3a10500c6674dffdfda`\n- `Linux >= 3e3b5dfcd16a3e254aab61bd1e8c417dd4503102 < 1ab526d97a57e44d26fadcc0e9adeb9c0c0182f5`\n- `Linux 5ef16d2d172ee56714cff37cd005b98aba08ef5a`\n- `Linux ff169909eac9e00bf1aa0af739ba6ddfb1b1d135`\n- `Linux 47244ac0b65bd74cc70007d8e1bac68bd2baad19`\n- `Linux c45cea83e13699bdfd47842e04d09dd43af4c371`\n- `Linux 307d2e6cebfca9d92f86c8e2c8e3dd4a8be46ba6`\n- `Linux >= 5.10.82 < 5.10.248`\n- `Linux >= 5.15.5 < 5.15.198`\n- `Linux >= 4.4.293 < 4.5`\n- `Linux >= 4.9.291 < 4.10`\n- `Linux >= 4.14.256 < 4.15`\n- `Linux >= 4.19.218 < 4.20`\n- `Linux >= 5.4.162 < 5.5`\n- `Linux 5.16`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}