ASB-A-380855429

See a problem?
Import Source
https://storage.googleapis.com/android-osv/ASB-A-380855429.json
JSON Data
https://api.osv.dev/v1/vulns/ASB-A-380855429
Aliases
Published
2025-04-01T00:00:00Z
Modified
2026-04-21T15:25:42.831358Z
Summary
[none]
Details

In binderaddfreeze_work of binder.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

References

Affected packages

Android / :linux_kernel:

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
:0
Fixed
:2025-04-05

Affected versions

Other
Kernel

Ecosystem specific

{
    "vanir_signatures": [
        {
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "113519457968663428999208588565149208277",
                    "170010042509868609093064495653733499150",
                    "287081010186543995319927861005993002505",
                    "229127503102060396528631827471930645155",
                    "11689548084189178092449762277363402699",
                    "308705181095334396650545508353199661537",
                    "29260424378624128962858238439959502242",
                    "70896399710500306485788527988469956839",
                    "53363189695888639846966353040402251777",
                    "13493924392500315384052105706430377807",
                    "318166828823032113599958020370579404951",
                    "232576272002824891944472990703476826977",
                    "104828980373488623326297477565762392975",
                    "143616812705682324535196470326086591925",
                    "93895699590936234032737886626640673819",
                    "261512501167427232020980221916131799687",
                    "111401035767074571420544699882214607823"
                ]
            },
            "id": "ASB-A-380855429-2394e407",
            "deprecated": false,
            "signature_version": "v1",
            "signature_type": "Line",
            "source": "https://android.googlesource.com/kernel/common/+/84ce22b0bcdb3c87ee36bc7213083aaf0de79e2e",
            "target": {
                "file": "drivers/android/binder.c"
            }
        },
        {
            "digest": {
                "threshold": 0.9,
                "line_hashes": [
                    "113519457968663428999208588565149208277",
                    "170010042509868609093064495653733499150",
                    "287081010186543995319927861005993002505",
                    "229127503102060396528631827471930645155",
                    "11689548084189178092449762277363402699",
                    "308705181095334396650545508353199661537",
                    "29260424378624128962858238439959502242",
                    "70896399710500306485788527988469956839",
                    "53363189695888639846966353040402251777",
                    "13493924392500315384052105706430377807",
                    "318166828823032113599958020370579404951",
                    "232576272002824891944472990703476826977",
                    "104828980373488623326297477565762392975",
                    "143616812705682324535196470326086591925",
                    "93895699590936234032737886626640673819",
                    "261512501167427232020980221916131799687",
                    "111401035767074571420544699882214607823"
                ]
            },
            "id": "ASB-A-380855429-939fd4c7",
            "deprecated": false,
            "signature_version": "v1",
            "signature_type": "Line",
            "source": "https://android.googlesource.com/kernel/common/+/a26cde405528cdf890f94956d4f61a19e3cc315d",
            "target": {
                "file": "drivers/android/binder.c"
            }
        },
        {
            "digest": {
                "length": 906.0,
                "function_hash": "262406987265569266840292832199140035606"
            },
            "id": "ASB-A-380855429-b8ceda2b",
            "deprecated": false,
            "signature_version": "v1",
            "signature_type": "Function",
            "source": "https://android.googlesource.com/kernel/common/+/84ce22b0bcdb3c87ee36bc7213083aaf0de79e2e",
            "target": {
                "function": "binder_add_freeze_work",
                "file": "drivers/android/binder.c"
            }
        },
        {
            "digest": {
                "length": 906.0,
                "function_hash": "262406987265569266840292832199140035606"
            },
            "id": "ASB-A-380855429-d68cc42c",
            "deprecated": false,
            "signature_version": "v1",
            "signature_type": "Function",
            "source": "https://android.googlesource.com/kernel/common/+/a26cde405528cdf890f94956d4f61a19e3cc315d",
            "target": {
                "function": "binder_add_freeze_work",
                "file": "drivers/android/binder.c"
            }
        }
    ],
    "fixes": [
        "https://android.googlesource.com/kernel/common/+/84ce22b0bcdb3c87ee36bc7213083aaf0de79e2e",
        "https://android.googlesource.com/kernel/common/+/a26cde405528cdf890f94956d4f61a19e3cc315d"
    ],
    "types": [
        "EoP"
    ],
    "spl": "2025-04-05",
    "severity": "High"
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-380855429.json"