PT-2026-64690 · Linux · Linux

CVE-2026-64469

·

Publicado

2026-07-25

·

Atualizado

2026-07-25

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
binder: fix UAF in binder thread release()
When a thread exits, binder thread release() walks its transaction stack to clear the t->from and t->to proc that correspond with the exiting thread. However, a process dying in parallel might attempt to kfree some of these transactions. And if one of them has no associated t->to proc, the t->to proc->inner lock will not be acquired.
This means that transaction accesses in binder thread release() after t->to proc has been cleared might race with binder free transaction() and cause a use-after-free error as reported by KASAN:
================================================================== BUG: KASAN: slab-use-after-free in binder thread release+0x5d0/0x798 Write of size 8 at addr ffff000016627500 by task X/715
CPU: 17 UID: 0 PID: 715 Comm: X Not tainted 7.1.0-rc5-00149-g8fde5d1d47f6 #30 PREEMPT Hardware name: linux,dummy-virt (DT) Call trace: binder thread release+0x5d0/0x798 binder ioctl+0x12c0/0x299c [...]
Allocated by task 717 on cpu 18 at 67.267803s: kasan kmalloc+0xa0/0xbc kmalloc cache noprof+0x174/0x444 binder transaction+0x554/0x8150 binder thread write+0xa30/0x4354 binder ioctl+0x20f0/0x299c [...]

Freed by task 202 on cpu 18 at 90.416221s: kasan slab free+0x58/0x80 kfree+0x1a0/0x4a4 binder free transaction+0x150/0x294 binder send failed reply+0x398/0x6d8 binder release work+0x3e4/0x4ec binder deferred func+0xbd8/0x104c [...]

In order to avoid this, make sure that binder free transaction() reads the t->to proc under the transaction lock. This will serialize the transaction release with the accesses in binder thread release(). Plus, it matches the documented locking rules for @to proc.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-64469

Produtos afetados

Linux