PT-2025-27896 · Linux+3 · Linux Kernel+3
Published
2025-05-24
·
Updated
2025-12-03
·
CVE-2025-38175
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions prior to 6.15.0-rc7-00138-g57483a362741
Description:
A use-after-free vulnerability has been identified in the Linux kernel, specifically in the binder devices list. The issue arises when devices are released without being removed from the list, allowing for potential exploitation. The vulnerability was addressed by ensuring that the device is removed from the binder devices list before being freed.
Recommendations:
For Linux kernel versions prior to 6.15.0-rc7-00138-g57483a362741, update to a version that includes the fix for the use-after-free vulnerability in the binder devices list. As a temporary workaround, consider restricting access to the binder remove device function until a patch is available.
Exploit
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Linux Kernel
Ubuntu