Back

HIGH

nfc: pn533: Fix use-after-free bugs caused by pn532_cmd_timeout

Published Jun 18, 2025

Description

When the pn532 uart device is detaching, the pn532_uart_remove() is called. But there are no functions in pn532_uart_remove() that could delete the cmd_timeout timer, which will cause use-after-free bugs. The process is shown below:

(thread 1) | (thread 2) | pn532_uart_send_frame pn532_uart_remove | mod_timer(&pn532->cmd_timeout,...) ... | (wait a time) kfree(pn532) //FREE | pn532_cmd_timeout | pn532_uart_send_frame | pn532->... //USE

This patch adds del_timer_sync() in pn532_uart_remove() in order to prevent the use-after-free bugs. What's more, the pn53x_unregister_nfc() is well synchronized, it sets nfc_dev->shutting_down to true and there are no syscalls could restart the cmd_timeout timer.

Affected products

Remediation

No remediation recorded yet.

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Jun 18, 2025
Updated May 11, 2026
Reserved Jun 18, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jun 18, 2025
ENISA EUVD
Assigner Linux
Published Jun 18, 2025
Updated May 11, 2026
Exploited since n/a
EUVD-2022-55284