PT-2026-64689 · Linux · Linux
CVE-2026-64468
·
Published
2026-07-25
·
Updated
2026-07-25
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
binder: fix UAF in binder free transaction()
In binder free transaction(), the t->to proc is read under the t->lock.
However, once the t->lock is dropped, the to proc can die in parallel.
This leads to a use-after-free error when we attempt to acquire its
inner lock right afterwards:
==================================================================
BUG: KASAN: slab-use-after-free in raw spin lock+0xe4/0x1a0
Write of size 4 at addr ffff00001125da70 by task B/672
CPU: 20 UID: 0 PID: 672 Comm: B Not tainted 7.1.0-rc6-00284-g8e65320d91cd #4 PREEMPT
Hardware name: linux,dummy-virt (DT)
Call trace:
raw spin lock+0xe4/0x1a0
binder free transaction+0x8c/0x320
binder send failed reply+0x21c/0x2f8
binder thread release+0x488/0x7e0
binder ioctl+0x12c0/0x29a0
[...]
Allocated by task 675:
kmalloc cache noprof+0x174/0x444
binder open+0x118/0xb70
do dentry open+0x374/0x1040
vfs open+0x58/0x3bc
[...]
Freed by task 212: kasan slab free+0x58/0x80 kfree+0x1a0/0x4a4 binder proc dec tmpref+0x32c/0x5e0 binder deferred func+0xc48/0x104c process one work+0x53c/0xbc0 [...]
To prevent this, pin the target thread (t->to thread) to guarantee the
target process remains alive. Undelivered transactions without a target
thread are already safe, as the target process can only be the current
context in those paths.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux