In binderaddfreeze_work of binder.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"vanir_signatures": [
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"113519457968663428999208588565149208277",
"170010042509868609093064495653733499150",
"287081010186543995319927861005993002505",
"229127503102060396528631827471930645155",
"11689548084189178092449762277363402699",
"308705181095334396650545508353199661537",
"29260424378624128962858238439959502242",
"70896399710500306485788527988469956839",
"53363189695888639846966353040402251777",
"13493924392500315384052105706430377807",
"318166828823032113599958020370579404951",
"232576272002824891944472990703476826977",
"104828980373488623326297477565762392975",
"143616812705682324535196470326086591925",
"93895699590936234032737886626640673819",
"261512501167427232020980221916131799687",
"111401035767074571420544699882214607823"
]
},
"id": "ASB-A-380855429-2394e407",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/kernel/common/+/84ce22b0bcdb3c87ee36bc7213083aaf0de79e2e",
"target": {
"file": "drivers/android/binder.c"
}
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"113519457968663428999208588565149208277",
"170010042509868609093064495653733499150",
"287081010186543995319927861005993002505",
"229127503102060396528631827471930645155",
"11689548084189178092449762277363402699",
"308705181095334396650545508353199661537",
"29260424378624128962858238439959502242",
"70896399710500306485788527988469956839",
"53363189695888639846966353040402251777",
"13493924392500315384052105706430377807",
"318166828823032113599958020370579404951",
"232576272002824891944472990703476826977",
"104828980373488623326297477565762392975",
"143616812705682324535196470326086591925",
"93895699590936234032737886626640673819",
"261512501167427232020980221916131799687",
"111401035767074571420544699882214607823"
]
},
"id": "ASB-A-380855429-939fd4c7",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://android.googlesource.com/kernel/common/+/a26cde405528cdf890f94956d4f61a19e3cc315d",
"target": {
"file": "drivers/android/binder.c"
}
},
{
"digest": {
"length": 906.0,
"function_hash": "262406987265569266840292832199140035606"
},
"id": "ASB-A-380855429-b8ceda2b",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/kernel/common/+/84ce22b0bcdb3c87ee36bc7213083aaf0de79e2e",
"target": {
"function": "binder_add_freeze_work",
"file": "drivers/android/binder.c"
}
},
{
"digest": {
"length": 906.0,
"function_hash": "262406987265569266840292832199140035606"
},
"id": "ASB-A-380855429-d68cc42c",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://android.googlesource.com/kernel/common/+/a26cde405528cdf890f94956d4f61a19e3cc315d",
"target": {
"function": "binder_add_freeze_work",
"file": "drivers/android/binder.c"
}
}
],
"fixes": [
"https://android.googlesource.com/kernel/common/+/84ce22b0bcdb3c87ee36bc7213083aaf0de79e2e",
"https://android.googlesource.com/kernel/common/+/a26cde405528cdf890f94956d4f61a19e3cc315d"
],
"types": [
"EoP"
],
"spl": "2025-04-05",
"severity": "High"
}