PT-2026-64689 · Linux · Linux

CVE-2026-64468

·

Published

2026-07-25

·

Updated

2026-07-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
binder: fix UAF in binder free transaction()
In binder free transaction(), the t->to proc is read under the t->lock. However, once the t->lock is dropped, the to proc can die in parallel. This leads to a use-after-free error when we attempt to acquire its inner lock right afterwards:
================================================================== BUG: KASAN: slab-use-after-free in raw spin lock+0xe4/0x1a0 Write of size 4 at addr ffff00001125da70 by task B/672
CPU: 20 UID: 0 PID: 672 Comm: B Not tainted 7.1.0-rc6-00284-g8e65320d91cd #4 PREEMPT Hardware name: linux,dummy-virt (DT) Call trace: raw spin lock+0xe4/0x1a0 binder free transaction+0x8c/0x320 binder send failed reply+0x21c/0x2f8 binder thread release+0x488/0x7e0 binder ioctl+0x12c0/0x29a0 [...]
Allocated by task 675: kmalloc cache noprof+0x174/0x444 binder open+0x118/0xb70 do dentry open+0x374/0x1040 vfs open+0x58/0x3bc [...]

Freed by task 212: kasan slab free+0x58/0x80 kfree+0x1a0/0x4a4 binder proc dec tmpref+0x32c/0x5e0 binder deferred func+0xc48/0x104c process one work+0x53c/0xbc0 [...]

To prevent this, pin the target thread (t->to thread) to guarantee the target process remains alive. Undelivered transactions without a target thread are already safe, as the target process can only be the current context in those paths.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-64468

Affected Products

Linux