CVE-2026-31509Patch(linux / linux_kernel)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix circular locking dependency in nci_close_device nci_close_device() flushes rx_wq and tx_wq while holding req_lock. This causes a circular locking dependency because nci_rx_work() running on rx_wq can end up taking req_lock too: nci_rx_work -> nci_rx_data_packet -> nci_data_exchange_complete -> __sk_destruct -> rawsock_destruct -> nfc_deactivate_target -> nci_deactivate_target -> nci_request -> mutex_lock(&ndev->req_lock) Move the flush of rx_wq after req_lock has been released. This should safe (I think) because NCI_UP has already been cleared and the transport is closed, so the work will see it and return -ENETDOWN. NIPA has been hitting this running the nci selftest with a debug kernel on roughly 4% of the runs.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-667

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-22); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

2 versions affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-22: 1Mentions · 2026-04-23: 1Patch / Workaround · 2026-04-22: 1Technical Details · 2026-04-22: 1Technical Details · 2026-04-23: 104-2204-23
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-221
Patch1
2026-04-231
Disclosure1
Full discourse2 posts
  • WindowsForum@windowsforum
    Disclosure

    🪟 Deadlocks: the “surprise” bug that makes PCs hang like they’re thinking. CVE-2026-31509 fixes a locking-order loop in NFC close—proof stability is just as critical as memory safety. https://windowsforum.com/threads/cve-2026-31509-linux-nfc-locking-fix-deadlock-risk-in-close-path.414810/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #LinuxKernel #ConcurrencyBug #NfcNci #Cve202631509 https://t.co/1HW4QYVoHh

    Post summary

    The post reports a deadlock issue (CVE‑2026‑31509) caused by a locking‑order loop in Linux NFC close, noting it has been addressed but without providing PoC or exploit details.

    0000048
    1.1K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-31509 In the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix circular locking dependency in nci_close_device nci_close_device() flushes rx_wq a… https://www.cve.org/CVERecord?id=CVE-2026-31509

    Post summary

    CVE‑2026‑31509, a circular locking issue in the Linux kernel’s NFC NCI subsystem, has been fixed and the vulnerability is no longer present. The announcement notes the specific code area affected and confirms the patch deployment.

    00000111
    57.2K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel3.2--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more