CVE-2025-38416
NFC: nci: uart: Set tty->disc_data only in success path
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
25 Jul 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In the Linux kernel, the following vulnerability has been resolved:
NFC: nci: uart: Set tty->disc_data only in success path
Setting tty->disc_data before opening the NCI device means we need to
clean it up on error paths. This also opens some short window if device
starts sending data, even before NCIUARTSETDRIVER IOCTL succeeded
(broken hardware?). Close the window by exposing tty->disc_data only on
the success path, when opening of the NCI device and try_module_get()
succeeds.
The code differs in error path in one aspect: tty->disc_data won't be
ever assigned thus NULL-ified. This however should not be relevant
difference, because of "tty->disc_data=NULL" in nci_uart_tty_open().
Affected products
Linux · LinuxWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://git.kernel.org/stable/c/000bfbc6bc334a93fffca8f5aa9583e7b6356cb5https://git.kernel.org/stable/c/55c3dbd8389636161090a2b2b6d2d709b9602e9chttps://git.kernel.org/stable/c/a514fca2b8e95838a3ba600f31a18fa60b76d893https://git.kernel.org/stable/c/a8acc7080ad55c5402a1b818b3008998247dda87https://git.kernel.org/stable/c/ac6992f72bd8e22679c1e147ac214de6a7093c23https://git.kernel.org/stable/c/dc7722619a9c307e9938d735cf4a2210d3d48dcbhttps://git.kernel.org/stable/c/e9799db771b2d574d5bf0dfb3177485e5f40d4d6https://git.kernel.org/stable/c/fc27ab48904ceb7e4792f0c400f1ef175edf16fehttps://lists.debian.org/debian-lts-announce/2025/10/msg00007.htmlhttps://lists.debian.org/debian-lts-announce/2025/10/msg00008.html