PT-2026-64689 · Linux · Linux

CVE-2026-64468

·

Publicado

2026-07-25

·

Atualizado

2026-07-25

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
binder: fix UAF in binder free transaction()
In binder free transaction(), the t->to proc is read under the t->lock. However, once the t->lock is dropped, the to proc can die in parallel. This leads to a use-after-free error when we attempt to acquire its inner lock right afterwards:
================================================================== BUG: KASAN: slab-use-after-free in raw spin lock+0xe4/0x1a0 Write of size 4 at addr ffff00001125da70 by task B/672
CPU: 20 UID: 0 PID: 672 Comm: B Not tainted 7.1.0-rc6-00284-g8e65320d91cd #4 PREEMPT Hardware name: linux,dummy-virt (DT) Call trace: raw spin lock+0xe4/0x1a0 binder free transaction+0x8c/0x320 binder send failed reply+0x21c/0x2f8 binder thread release+0x488/0x7e0 binder ioctl+0x12c0/0x29a0 [...]
Allocated by task 675: kmalloc cache noprof+0x174/0x444 binder open+0x118/0xb70 do dentry open+0x374/0x1040 vfs open+0x58/0x3bc [...]

Freed by task 212: kasan slab free+0x58/0x80 kfree+0x1a0/0x4a4 binder proc dec tmpref+0x32c/0x5e0 binder deferred func+0xc48/0x104c process one work+0x53c/0xbc0 [...]

To prevent this, pin the target thread (t->to thread) to guarantee the target process remains alive. Undelivered transactions without a target thread are already safe, as the target process can only be the current context in those paths.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-64468

Produtos afetados

Linux