CVE-2026-31509 Details
Description
In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix circular locking dependency in nci_close_device nci_close_device() flushes rx_wq and tx_wq while holding req_lock. This causes a circular locking dependency because nci_rx_work() running on rx_wq can end up taking req_lock too: nci_rx_work -> nci_rx_data_packet -> nci_data_exchange_complete -> __sk_destruct -> rawsock_destruct -> nfc_deactivate_target -> nci_deactivate_target -> nci_request -> mutex_lock(&ndev->req_lock) Move the flush of rx_wq after req_lock has been released. This should safe (I think) because NCI_UP has already been cleared and the transport is closed, so the work will see it and return -ENETDOWN. NIPA has been hitting this running the nci selftest with a debug kernel on roughly 4% of the runs.
A circular locking dependency vulnerability has been identified in the Linux kernel's NFC NCI protocol implementation. The issue arises in the 'nci_close_device' function, which flushes the receive and transmit work queues while holding a lock on the request. This can create a deadlock situation, as the receive work can end up trying to acquire the same lock, leading to a circular dependency. The vulnerability has been observed to occur in approximately 4% of the runs during the NCI self-test with a debug kernel.
The vulnerability has been addressed in a patch that is included in the official Linux kernel repository. Instructions for applying the patch can be found in the Linux kernel Git repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/09143c0e8f3b03517e6233aad42f45c794d8df8e | kernel.org | Patch |
| https://git.kernel.org/stable/c/1edc12d2bbcb7a8d0f1088e6fccb9d8c01bb1289 | kernel.org | Patch |
| https://git.kernel.org/stable/c/4527025d440ce84bf56e75ce1df2e84cb8178616 | kernel.org | Patch |
| https://git.kernel.org/stable/c/5eef9ebec7f5738f12cadede3545c05b34bf5ac3 | kernel.org | Patch |
| https://git.kernel.org/stable/c/7ed00a3edc8597fe2333f524401e2889aa1b5edf | kernel.org | Patch |
| https://git.kernel.org/stable/c/ca54e904a071aa65ef3ad46ba42d51aaac6b73b4 | kernel.org | Patch |
| https://git.kernel.org/stable/c/d89b74bf08f067b55c03d7f999ba0a0e73177eb3 | kernel.org | Patch |
| https://git.kernel.org/stable/c/eb435d150ca74b4d40f77f1a2266f3636ed64a79 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-667 | Improper Locking | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 3.2.1, < 5.10.253 >= 5.11, < 5.15.203 >= 5.16, < 6.1.168 >= 6.2, < 6.6.131 >= 6.7, < 6.12.80 >= 6.13, < 6.18.21 >= 6.19, < 6.19.11 3.2 - 7.0 rc1 7.0 rc2 7.0 rc3 7.0 rc4 7.0 rc5 7.0 rc6 7.0 rc7 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Apr 28, 2026 | Initial Analysis | [email protected] |
| Apr 22, 2026 | New CVE Received | kernel.org |