PT-2024-36860 · Linux · Linux Kernel

Published

2024-10-13

·

Updated

2025-04-01

·

CVE-2024-56556

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to the fixed version
Description A use-after-free vulnerability has been identified in the Linux kernel, specifically in the binder add freeze work() function. This issue arises when the proc->inner lock is temporarily dropped to acquire the node->lock, allowing a race condition with binder node release() that can trigger a use-after-free. The vulnerability is related to the binder subsystem and can be exploited by malicious actors.
Recommendations To resolve this issue, update the Linux kernel to a version that includes the fix for the use-after-free vulnerability in binder add freeze work(). As a temporary workaround, consider restricting access to the binder subsystem to minimize the risk of exploitation.

Exploit

Fix

Use After Free

Race Condition

Weakness Enumeration

Related Identifiers

ASB-A-380855429
BDU:2025-07230
CVE-2024-56556

Affected Products

Linux Kernel