CVE-2026-23291 PUBLISHED

nfc: pn533: properly drop the usb interface reference on disconnect

Assigner: Linux
Reserved: 13.01.2026 Published: 25.03.2026 Updated: 25.03.2026

In the Linux kernel, the following vulnerability has been resolved:

nfc: pn533: properly drop the usb interface reference on disconnect

When the device is disconnected from the driver, there is a "dangling" reference count on the usb interface that was grabbed in the probe callback. Fix this up by properly dropping the reference after we are done with it.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from c46ee38620a2aa2b25b16bc9738ace80dbff76a4 to 7398d6570501edc55a50ece820f369ab3c1df2e7 (excl.)
  • affected from c46ee38620a2aa2b25b16bc9738ace80dbff76a4 to d1f6d20b3c2642ec85ce6ea5da7155746c31c6d0 (excl.)
  • affected from c46ee38620a2aa2b25b16bc9738ace80dbff76a4 to 7ff14eb070f0efecb2606f8d7aa01b77d188e886 (excl.)
  • affected from c46ee38620a2aa2b25b16bc9738ace80dbff76a4 to 00477cab053dc4816b99141d8fcca7a479cfebeb (excl.)
  • affected from c46ee38620a2aa2b25b16bc9738ace80dbff76a4 to 4551d6cea00224ab65a0ef35e4e6da0e9c0a2d74 (excl.)
  • affected from c46ee38620a2aa2b25b16bc9738ace80dbff76a4 to 12133a483dfa832241fbbf09321109a0ea8a520e (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 3.1 is affected
  • unaffected from 0 to 3.1 (excl.)
  • unaffected from 6.1.167 to 6.1.* (incl.)
  • unaffected from 6.6.130 to 6.6.* (incl.)
  • unaffected from 6.12.77 to 6.12.* (incl.)
  • unaffected from 6.18.17 to 6.18.* (incl.)
  • unaffected from 6.19.7 to 6.19.* (incl.)
  • unaffected from 7.0-rc2 to * (incl.)

References