---
id: CVE-2026-90225
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  nfc: llcp: read llcp_sock->local under the socket lock in getsockopt

  nfc_llcp_getsockopt() read llcp_sock->local before lock_sock(sk) and
  then dereferenced the cached …
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  nfc: llcp: read llcp_sock->local under the socket lock in getsockopt

  nfc_llcp_getsockopt() read llcp_sock->local before lock_sock(sk) and
  then dereferenced the cached …
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 <
    56fd158fef20268f48db6cdfe5d722e930134eda
  - >-
    Linux >= 26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 <
    8ba8cec0586727cc135ca4827921fc7b52946d71
  - >-
    Linux >= 26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 <
    ed5240bab3468988077fe8bf29b935eaecc9ff89
  - >-
    Linux >= 26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 <
    fe65727a4a21b11c18eebae1338482767a897b76
  - >-
    Linux >= 26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 <
    2d8ac24565be85bf56580b87bf1b874d35625eb5
  - >-
    Linux >= 26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 <
    156e65bd29307f5053835bff60bc1ba342fa010f
  - >-
    Linux >= 26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 <
    d1b73962675cdc5a58e2707e25b548d8b495fde0
  - >-
    Linux >= 26fd76cab2e61cedc5c25f7151fb31b57ddc53c7 <
    36812527052c5bfb1ec6c1e292d67a5bf76b750f
  - Linux 3.10
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T18:17:47.320'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90225'
references:
  - url: 'https://git.kernel.org/stable/c/156e65bd29307f5053835bff60bc1ba342fa010f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/2d8ac24565be85bf56580b87bf1b874d35625eb5'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/36812527052c5bfb1ec6c1e292d67a5bf76b750f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/56fd158fef20268f48db6cdfe5d722e930134eda'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8ba8cec0586727cc135ca4827921fc7b52946d71'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d1b73962675cdc5a58e2707e25b548d8b495fde0'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ed5240bab3468988077fe8bf29b935eaecc9ff89'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/fe65727a4a21b11c18eebae1338482767a897b76'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
epss: 0.00164
epssPercentile: 0.06017
ingestedAt: '2026-09-17T16:21:47.853Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

nfc: llcp: read llcp_sock->local under the socket lock in getsockopt

nfc_llcp_getsockopt() read llcp_sock->local before lock_sock(sk) and
then dereferenced the cached pointer inside the locked region.
llcp_sock_bind() assigns and clears llcp_sock->local under the same
socket lock, dropping the last reference on its error path. A
getsockopt() racing an in-flight bind() can observe the pointer, block
on lock_sock(), and then dereference a freed nfc_llcp_local once bind()
has unwound.

Move the llcp_sock->local read and the NULL check inside the
lock_sock(sk) region so bind() cannot mutate or free the pointer between
the load and the use.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
