CVE-2025-71079None▾ SunlitIn the Linux kernel, the following vulnerability has been resolved: net: nfc: fix deadlock between nfc_unregister_device and rfkill_fop_write A deadlock can occur between nfc_unregister_device() and rfkill_fop_write() due to lock order…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CVEORG
Last analysed / modified upstream
0.09%
0.09% → 0.1%
In the Linux kernel, the following vulnerability has been resolved:
net: nfc: fix deadlock between nfc_unregister_device and rfkill_fop_write
A deadlock can occur between nfc_unregister_device() and rfkill_fop_write() due to lock ordering inversion between device_lock and rfkill_global_mutex.
The problematic lock order is:
Thread A (rfkill_fop_write): rfkill_fop_write() mutex_lock(&rfkill_global_mutex) rfkill_set_block() nfc_rfkill_set_block() nfc_dev_down() device_lock(&dev->dev) <- waits for device_lock
Thread B (nfc_unregister_device): nfc_unregister_device() device_lock(&dev->dev) rfkill_unregister() mutex_lock(&rfkill_global_mutex) <- waits for rfkill_global_mutex
This creates a classic ABBA deadlock scenario.
Fix this by moving rfkill_unregister() and rfkill_destroy() outside the device_lock critical section. Store the rfkill pointer in a local variable before releasing the lock, then call rfkill_unregister() after releasing device_lock.
This change is safe because rfkill_fop_write() holds rfkill_global_mutex while calling the rfkill callbacks, and rfkill_unregister() also acquires rfkill_global_mutex before cleanup. Therefore, rfkill_unregister() will wait for any ongoing callback to complete before proceeding, and device_del() is only called after rfkill_unregister() returns, preventing any use-after-free.
The similar lock ordering in nfc_register_device() (device_lock -> rfkill_global_mutex via rfkill_register) is safe because during registration the device is not yet in rfkill_list, so no concurrent rfkill operations can occur on this device.
Linux >= 73a0d12114b4bc1a9def79a623264754b9df698e < 2e0831e9fc46a06daa6d4d8d57a2738e343130c3Linux >= 8a9c61c3ef187d8891225f9b932390670a43a0d3 < e02a1c33f10a0ed3aba855ab8ae2b6c4c5be8012Linux >= 3e3b5dfcd16a3e254aab61bd1e8c417dd4503102 < ee41f4f3ccf8cd6ba3732e867abbec7e6d8d12e5Linux >= 3e3b5dfcd16a3e254aab61bd1e8c417dd4503102 < 6b93c8ab6f6cda8818983a4ae3fcf84b023037b4Linux >= 3e3b5dfcd16a3e254aab61bd1e8c417dd4503102 < 8fc4632fb508432895430cd02b38086bdd649083Linux >= 3e3b5dfcd16a3e254aab61bd1e8c417dd4503102 < f3a8a7c1aa278f2378b2f3a10500c6674dffdfdaLinux >= 3e3b5dfcd16a3e254aab61bd1e8c417dd4503102 < 1ab526d97a57e44d26fadcc0e9adeb9c0c0182f5Linux 5ef16d2d172ee56714cff37cd005b98aba08ef5aLinux ff169909eac9e00bf1aa0af739ba6ddfb1b1d135Linux 47244ac0b65bd74cc70007d8e1bac68bd2baad19Linux c45cea83e13699bdfd47842e04d09dd43af4c371Linux 307d2e6cebfca9d92f86c8e2c8e3dd4a8be46ba6Linux >= 5.10.82 < 5.10.248Linux >= 5.15.5 < 5.15.198Linux >= 4.4.293 < 4.5Linux >= 4.9.291 < 4.10Linux >= 4.14.256 < 4.15Linux >= 4.19.218 < 4.20Linux >= 5.4.162 < 5.5Linux 5.16Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-68286NoneIn the Linux kernel, the following vulnerability has been resolved: drop_monitor: perform u64_stats updates under IRQ-disabled section In net_dm_packet_trace_kfree_skb_hit() and net_dm_hw_trap_packet_probe(), u64_stats_update_begin() /…
CVE-2026-68337NoneIn the Linux kernel, the following vulnerability has been resolved: bpf: Reject redirect helpers without a bpf_net_context The bpf_redirect*() helpers and skb_do_redirect() obtain the per-task bpf_redirect_info via bpf_net_ctx_get_ri()…
CVE-2026-68287High· 7.5In the Linux kernel, the following vulnerability has been resolved: drop_monitor: fix size calculations for 64-bit attributes net_dm_packet_report_fill() and net_dm_hw_packet_report_fill() use nla_put_u64_64bit() to append 64-bit attri…
CVE-2026-68288NoneIn the Linux kernel, the following vulnerability has been resolved: net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD net_dm_packet_report_fill() and net_dm_hw_packet_report_fill() open code the NET_DM_ATTR_PAYLOAD attribute to a…
CVE-2026-68289NoneIn the Linux kernel, the following vulnerability has been resolved: tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() In tipc_recvmsg(), the copy length is computed as: copy = min_t(int, dlen - offset, buflen); buf…
CVE-2026-68303NoneIn the Linux kernel, the following vulnerability has been resolved: drm/vc4: hvs/v3d: Fix null dereference in unbind The hvs and v3d drivers use dev_get_drvdata(master) in their unbind functions