[PATCH] nfc: llcp: fix socket list self-loop and soft lockup on bound connect
From: Henry Martin
Date: Fri Oct 09 2026 - 05:24:14 EST
llcp_sock_connect() rejects LLCP_CONNECTED and LLCP_CONNECTING but
not LLCP_BOUND, so a bind() followed by connect() links the same
sk->sk_node into both local->sockets and local->connecting_sockets.
When the peer answers with CC, nfc_llcp_recv_cc() removes the node
from the connecting list and re-adds it to the sockets list, where the
stale bind-time linkage turns the node into a self-loop; every later
sk_for_each() over local->sockets then spins forever (soft lockup) and
the socket refcount leaks.
Reject connect() in LLCP_BOUND state like the CONNECTED/CONNECTING
cases (a bound socket must be closed or unbound before connecting to
another service). Failing fast is also the only honest option: by the
time the error path could restore the binding, connect() had already
overwritten the bound service name and the unwind destroys the bound
session regardless.
This vulnerability was discovered by Tencent CodeBuddy Security.
Cc: stable@xxxxxxxxxxxxxxx
Fixes: a69f32af86e3 ("NFC: Socket linked list")
Signed-off-by: Henry Martin <bsdhenrymartin@xxxxxxxxx>
---
net/nfc/llcp_sock.c | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/net/nfc/llcp_sock.c b/net/nfc/llcp_sock.c
index 1e5ee4bcde684..33afd85f931a1 100644
--- a/net/nfc/llcp_sock.c
+++ b/net/nfc/llcp_sock.c
@@ -714,6 +714,15 @@
ret = -EINPROGRESS;
goto error;
}
+ /* A bound socket is already linked into local->sockets; letting
+ * it connect() would link the same sk->sk_node into
+ * local->connecting_sockets too, and the CC handler's re-add turns
+ * it into a self-loop. Reject like CONNECTED/CONNECTING.
+ */
+ if (sk->sk_state == LLCP_BOUND) {
+ ret = -EISCONN;
+ goto error;
+ }
dev = nfc_get_device(addr->dev_idx);
if (dev == NULL) {
--
2.43.7