PT-2026-64690 · Linux · Linux
CVE-2026-64469
·
Publicado
2026-07-25
·
Atualizado
2026-07-25
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
binder: fix UAF in binder thread release()
When a thread exits, binder thread release() walks its transaction stack
to clear the t->from and t->to proc that correspond with the exiting
thread. However, a process dying in parallel might attempt to kfree some
of these transactions. And if one of them has no associated t->to proc,
the t->to proc->inner lock will not be acquired.
This means that transaction accesses in binder thread release() after
t->to proc has been cleared might race with binder free transaction()
and cause a use-after-free error as reported by KASAN:
==================================================================
BUG: KASAN: slab-use-after-free in binder thread release+0x5d0/0x798
Write of size 8 at addr ffff000016627500 by task X/715
CPU: 17 UID: 0 PID: 715 Comm: X Not tainted 7.1.0-rc5-00149-g8fde5d1d47f6 #30 PREEMPT
Hardware name: linux,dummy-virt (DT)
Call trace:
binder thread release+0x5d0/0x798
binder ioctl+0x12c0/0x299c
[...]
Allocated by task 717 on cpu 18 at 67.267803s:
kasan kmalloc+0xa0/0xbc
kmalloc cache noprof+0x174/0x444
binder transaction+0x554/0x8150
binder thread write+0xa30/0x4354
binder ioctl+0x20f0/0x299c
[...]
Freed by task 202 on cpu 18 at 90.416221s: kasan slab free+0x58/0x80 kfree+0x1a0/0x4a4 binder free transaction+0x150/0x294 binder send failed reply+0x398/0x6d8 binder release work+0x3e4/0x4ec binder deferred func+0xbd8/0x104c [...]
In order to avoid this, make sure that binder free transaction() reads
the t->to proc under the transaction lock. This will serialize the
transaction release with the accesses in binder thread release(). Plus,
it matches the documented locking rules for @to proc.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux