{"id":"CVE-2026-90225","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: llcp: read llcp_sock->local under the socket lock in getsockopt\n\nnfc_llcp_getsockopt() read llcp_sock->local before lock_sock(sk) and\nthen dereferenced the cached …","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: llcp: read llcp_sock->local under the socket lock in getsockopt\n\nnfc_llcp_getsockopt() read llcp_sock->local before lock_sock(sk) and\nthen dereferenced the cached …","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","vendor":"Linux","product":"Linux","affected":["Linux >= 26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 < 56fd158fef20268f48db6cdfe5d722e930134eda","Linux >= 26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 < 8ba8cec0586727cc135ca4827921fc7b52946d71","Linux >= 26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 < ed5240bab3468988077fe8bf29b935eaecc9ff89","Linux >= 26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 < fe65727a4a21b11c18eebae1338482767a897b76","Linux >= 26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 < 2d8ac24565be85bf56580b87bf1b874d35625eb5","Linux >= 26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 < 156e65bd29307f5053835bff60bc1ba342fa010f","Linux >= 26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 < d1b73962675cdc5a58e2707e25b548d8b495fde0","Linux >= 26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 < 36812527052c5bfb1ec6c1e292d67a5bf76b750f","Linux 3.10"],"published":"2026-09-17","updated":"2026-09-18","sourceUpdated":"2026-09-18T18:17:47.320","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90225","references":[{"url":"https://git.kernel.org/stable/c/156e65bd29307f5053835bff60bc1ba342fa010f","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/2d8ac24565be85bf56580b87bf1b874d35625eb5","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/36812527052c5bfb1ec6c1e292d67a5bf76b750f","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/56fd158fef20268f48db6cdfe5d722e930134eda","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8ba8cec0586727cc135ca4827921fc7b52946d71","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d1b73962675cdc5a58e2707e25b548d8b495fde0","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/ed5240bab3468988077fe8bf29b935eaecc9ff89","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fe65727a4a21b11c18eebae1338482767a897b76","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"epss":0.00164,"epssPercentile":0.06022,"ingestedAt":"2026-09-17T16:21:47.853Z","slug":"CVE-2026-90225","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnfc: llcp: read llcp_sock->local under the socket lock in getsockopt\n\nnfc_llcp_getsockopt() read llcp_sock->local before lock_sock(sk) and\nthen dereferenced the cached pointer inside the locked region.\nllcp_sock_bind() assigns and clears llcp_sock->local under the same\nsocket lock, dropping the last reference on its error path. A\ngetsockopt() racing an in-flight bind() can observe the pointer, block\non lock_sock(), and then dereference a freed nfc_llcp_local once bind()\nhas unwound.\n\nMove the llcp_sock->local read and the NULL check inside the\nlock_sock(sk) region so bind() cannot mutate or free the pointer between\nthe load and the use.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":207189,"id":"CVE-2026-90225","ts":1789757339508,"field":"cvss","old":null,"new":"7.8"},{"seq":207188,"id":"CVE-2026-90225","ts":1789757339508,"field":"severity","old":"none","new":"high"}]}