net: nfc: fix deadlock between nfc_unregister_device and rfkill_fop_write
Published Jan 13, 2026
5.5
MEDIUMCVSS 3.1
EPSS 0.10%
Description
A deadlock can occur between nfc_unregister_device() and rfkill_fop_write() due to lock ordering inversion between device_lock and rfkill_global_mutex.
The problematic lock order is:
Thread A (rfkill_fop_write): rfkill_fop_write() mutex_lock(&rfkill_global_mutex) rfkill_set_block() nfc_rfkill_set_block() nfc_dev_down() device_lock(&dev->dev) <- waits for device_lock
Thread B (nfc_unregister_device): nfc_unregister_device() device_lock(&dev->dev) rfkill_unregister() mutex_lock(&rfkill_global_mutex) <- waits for rfkill_global_mutex
This creates a classic ABBA deadlock scenario.
Fix this by moving rfkill_unregister() and rfkill_destroy() outside the device_lock critical section. Store the rfkill pointer in a local variable before releasing the lock, then call rfkill_unregister() after releasing device_lock.
This change is safe because rfkill_fop_write() holds rfkill_global_mutex while calling the rfkill callbacks, and rfkill_unregister() also acquires rfkill_global_mutex before cleanup. Therefore, rfkill_unregister() will wait for any ongoing callback to complete before proceeding, and device_del() is only called after rfkill_unregister() returns, preventing any use-after-free.
The similar lock ordering in nfc_register_device() (device_lock -> rfkill_global_mutex via rfkill_register) is safe because during registration the device is not yet in rfkill_list, so no concurrent rfkill operations can occur on this device.
Affected products
-
- Version StatusaffectedConstraints-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints-
- Version StatusaffectedConstraints-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints-
- Version StatusaffectedConstraints-
- Version
-
- Version 4.14.256StatusaffectedConstraints<4.15
- Version 4.19.218StatusaffectedConstraints<4.20
- Version 4.4.293StatusaffectedConstraints<4.5
- Version 4.9.291StatusaffectedConstraints<4.10
- Version 5.10.82StatusaffectedConstraints<5.10.248
- Version 5.15.5StatusaffectedConstraints<5.15.198
- Version 5.4.162StatusaffectedConstraints<5.5
- Version
-
- Version 5.16StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.16
- Version 5.10.248StatusunaffectedConstraints<=5.10.*
- Version 5.15.198StatusunaffectedConstraints<=5.15.*
- Version 6.1.160StatusunaffectedConstraints<=6.1.*
- Version 6.12.64StatusunaffectedConstraints<=6.12.*
- Version 6.18.4StatusunaffectedConstraints<=6.18.*
- Version 6.19StatusunaffectedConstraints<=*
- Version 6.6.120StatusunaffectedConstraints<=6.6.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||||||||
| Linux | Linux | unaffected |
| |||||||||||||||||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 4.4.293 · < 4.5
- ≥ 4.9.291 · < 4.10
- ≥ 4.14.256 · < 4.15
- ≥ 4.19.218 · < 4.20
- ≥ 5.4.162 · < 5.5
- ≥ 5.10.82 · < 5.10.248
- ≥ 5.15.5 · < 5.15.198
- ≥ 5.16.1 · < 6.1.160
- ≥ 6.2 · < 6.6.120
- ≥ 6.7 · < 6.12.64
- ≥ 6.13 · < 6.18.4
- 5.16
- 6.19
- 6.19
- 6.19
- 6.19
- 6.19
- 6.19
- 6.19
- 6.19
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Jan–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.10% (0.00102) | 0.85th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.09% (0.00089) | 0.53th | v5 (v2026.06.15) |
| Jan 14, 2026 | 0.02% (0.00018) | 3.87th | v4 (v2025.03.14) |
References (13)
- https://access.redhat.com/security/cve/CVE-2025-71079 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2429121 Issue Tracking
- https://cert-portal.siemens.com/productcert/html/ssa-019113.html
- https://git.kernel.org/stable/c/1ab526d97a57e44d26fadcc0e9adeb9c0c0182f5 Patch
- https://git.kernel.org/stable/c/2e0831e9fc46a06daa6d4d8d57a2738e343130c3 Patch
- https://git.kernel.org/stable/c/6b93c8ab6f6cda8818983a4ae3fcf84b023037b4 Patch
- https://git.kernel.org/stable/c/8fc4632fb508432895430cd02b38086bdd649083 Patch
- https://git.kernel.org/stable/c/e02a1c33f10a0ed3aba855ab8ae2b6c4c5be8012 Patch
- https://git.kernel.org/stable/c/ee41f4f3ccf8cd6ba3732e867abbec7e6d8d12e5 Patch
- https://git.kernel.org/stable/c/f3a8a7c1aa278f2378b2f3a10500c6674dffdfda Patch
- https://lore.kernel.org/linux-cve-announce/2026011338-CVE-2025-71079-9f24@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2025-71079
- https://www.cve.org/CVERecord?id=CVE-2025-71079
Change history (0)
No recorded changes yet.