PT-2026-64689 · Linux · Linux
CVE-2026-64468
·
Publicado
2026-07-25
·
Atualizado
2026-07-25
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
binder: fix UAF in binder free transaction()
In binder free transaction(), the t->to proc is read under the t->lock.
However, once the t->lock is dropped, the to proc can die in parallel.
This leads to a use-after-free error when we attempt to acquire its
inner lock right afterwards:
==================================================================
BUG: KASAN: slab-use-after-free in raw spin lock+0xe4/0x1a0
Write of size 4 at addr ffff00001125da70 by task B/672
CPU: 20 UID: 0 PID: 672 Comm: B Not tainted 7.1.0-rc6-00284-g8e65320d91cd #4 PREEMPT
Hardware name: linux,dummy-virt (DT)
Call trace:
raw spin lock+0xe4/0x1a0
binder free transaction+0x8c/0x320
binder send failed reply+0x21c/0x2f8
binder thread release+0x488/0x7e0
binder ioctl+0x12c0/0x29a0
[...]
Allocated by task 675:
kmalloc cache noprof+0x174/0x444
binder open+0x118/0xb70
do dentry open+0x374/0x1040
vfs open+0x58/0x3bc
[...]
Freed by task 212: kasan slab free+0x58/0x80 kfree+0x1a0/0x4a4 binder proc dec tmpref+0x32c/0x5e0 binder deferred func+0xc48/0x104c process one work+0x53c/0xbc0 [...]
To prevent this, pin the target thread (t->to thread) to guarantee the
target process remains alive. Undelivered transactions without a target
thread are already safe, as the target process can only be the current
context in those paths.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux