CVE-2026-31629: Linux Kernel

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: add missing return after LLCP_CLOSED checks In nfc_llcp_recv_hdlc() and nfc_llcp_recv_disc(), when the socket state is LLCP_CLOSED, the code correctly calls release_sock() and nfc_llcp_sock_put() but fails to return. Execution falls through to the remainder of the function, which calls release_sock() and nfc_llcp_sock_put() again. This results in a double release_sock() and a refcount underflow via double nfc_llcp_sock_put(), leading to a use-after-free. Add the missing return statements after the LLCP_CLOSED branches in both functions to prevent the fall-through.

Affected products

  • Linux Linux Kernel: from 3.3, before 6.6.136 (fixed in 6.6.136); from 6.7, before 6.12.83 (fixed in 6.12.83); from 6.13, before 6.18.24 (fixed in 6.18.24); from 6.19, before 6.19.14 (fixed in 6.19.14); from 7.0, before 7.0.1 (fixed in 7.0.1)

Published 2026-04-24. Last modified 2026-06-17.