In the Linux kernel, the following vulnerability has been resolved:
nfc: st-nci: Fix use after free bug in ndlc_remove due to race condition
This bug influences both st_nci_i2c_remove and st_nci_spi_remove. Take st_nci_i2c_remove as an example.
In st_nci_i2c_probe, it called ndlc_probe and bound &ndlc->sm_work with llt_ndlc_sm_work.
When it calls ndlc_recv or timeout handler, it will finally call schedule_work to start the work.
When we call st_nci_i2c_remove to remove the driver, there may be a sequence as follows:
Fix it by finishing the work before cleanup in ndlc_remove
CPU0 CPU1
|llt_ndlc_sm_work st_nci_i2c_remove | ndlc_remove | st_nci_remove | nci_free_device| kfree(ndev) | //free ndlc->ndev | |llt_ndlc_rcv_queue |nci_recv_frame |//use ndlc->ndev
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | May 5, 2025 | May 2, 2025 |
| Ubuntu | — | Upgrade linux-azure-5.15Upgrade linux-intel-iot-realtimeUpgrade linux-ibm-5.4Upgrade linux-ibmUpgrade linux-raspi-5.4Upgrade linux-aws-fipsUpgrade linux-azure-4.15Upgrade linux-intel-iotgUpgrade linux-lts-xenialUpgrade linux-azure-5.4Upgrade linux-awsUpgrade linux-nvidia-tegra-igxUpgrade linux-riscv-5.15Upgrade linux-gcp-5.4Upgrade linux-hwe-5.4Upgrade linux-gcp-fipsUpgrade linux-bluefieldUpgrade linux-gcp-4.15Upgrade linux-ibm-5.15Upgrade linux-hweUpgrade linux-gcpUpgrade linux-gkeopUpgrade linux-gkeUpgrade linux-nvidia-tegraUpgrade linux-oracle-5.15Upgrade linux-lowlatencyUpgrade linux-aws-hweUpgrade linux-xilinx-zynqmpUpgrade linux-kvmUpgrade linuxUpgrade linux-fipsUpgrade linux-aws-5.4Upgrade linux-gcp-5.15Upgrade linux-oracleUpgrade linux-nvidiaUpgrade linux-intel-iotg-5.15Upgrade linux-azure-fipsUpgrade linux-nvidia-tegra-5.15Upgrade linux-azure-fdeUpgrade linux-realtimeUpgrade linux-azureUpgrade linux-lowlatency-hwe-5.15Upgrade linux-hwe-5.15Upgrade linux-iotUpgrade linux-oracle-5.4Upgrade linux-aws-5.15Upgrade linux-raspi | May 8, 2025 | May 2, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | May 2, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub