[PATCH] nfc: llcp: clear device pointer on disconnect
From: Aldo Ariel Panzardo
Date: Sat Sep 26 2026 - 17:21:31 EST
nfc_llcp_recv_disc() drops the device reference via nfc_put_device()
when a connected socket receives a DISC PDU, but does not clear
llcp_sock->dev. If the socket is later reconnected, any cleanup code
that checks llcp_sock->dev will find a non-NULL pointer and attempt a
second nfc_put_device(), underflowing the device refcount.
Clear the pointer immediately after the put so that a subsequent
reconnect does not double-release the device.
Fixes: d646960f7986 ("NFC: Initial LLCP support")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Aldo Ariel Panzardo <qwe.aldo@xxxxxxxxx>
---
net/nfc/llcp_core.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/net/nfc/llcp_core.c b/net/nfc/llcp_core.c
index 74bf81700..199543c47 100644
--- a/net/nfc/llcp_core.c
+++ b/net/nfc/llcp_core.c
@@ -1220,6 +1220,7 @@ static void nfc_llcp_recv_disc(struct nfc_llcp_local *local,
if (sk->sk_state == LLCP_CONNECTED) {
nfc_put_device(local->dev);
+ llcp_sock->dev = NULL;
sk->sk_state = LLCP_CLOSED;
sk->sk_state_change(sk);
}
--
2.43.0