PT-2024-1001 · Linux+4 · Linux Kernel+4

Carlos Llamas

·

Published

2024-04-11

·

Updated

2025-12-23

·

CVE-2024-26926

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the binder component in the Linux kernel, where a vulnerability has been resolved by checking offset alignment in the binder get object() function. This check was unintentionally removed due to changes in how binder objects are copied, specifically with the introduction of commit 6d98eb95b450. The removal of the offset alignment check could lead to complications when unwinding objects. The vulnerability is related to a use-after-free issue in binder alloc copy to buffer of binder.c, which could result in arbitrary code execution and local escalation of privilege in the kernel. The exploitation of this vulnerability does not require additional execution privileges or user interaction. It involves crafting a malicious binder object with misaligned offsets and sending it through IPC, allowing the object to bypass alignment validation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ASB-A-320661088
BDU:2024-09340
CVE-2024-26926
DLA-3842-1
DSA-5680-1
DSA-5681-1
OESA-2024-1650
OESA-2024-1651
OESA-2024-1652
USN-6893-1
USN-6893-2
USN-6893-3
USN-6895-1
USN-6895-2
USN-6895-3
USN-6895-4
USN-6896-1
USN-6896-2
USN-6896-3
USN-6896-4
USN-6896-5
USN-6898-1
USN-6898-2
USN-6898-3
USN-6898-4
USN-6900-1
USN-6917-1
USN-6918-1
USN-6919-1
USN-6927-1
USN-7019-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Ubuntu