CVE-2026-23184

Source
https://cve.org/CVERecord?id=CVE-2026-23184
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23184.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-23184
Downstream
Published
2026-02-14T16:27:14.167Z
Modified
2026-02-14T20:07:07.707150Z
Summary
binder: fix UAF in binder_netlink_report()
Details

In the Linux kernel, the following vulnerability has been resolved:

binder: fix UAF in bindernetlinkreport()

Oneway transactions sent to frozen targets via binderproctransaction() return a BRTRANSACTIONPENDINGFROZEN error but they are still treated as successful since the target is expected to thaw at some point. It is then not safe to access 't' after BRTRANSACTIONPENDINGFROZEN errors as the transaction could have been consumed by the now thawed target.

This is the case for bindernetlinkreport() which derreferences 't' after a pending frozen error, as pointed out by the following KASAN report:

================================================================== BUG: KASAN: slab-use-after-free in bindernetlinkreport.isra.0+0x694/0x6c8 Read of size 8 at addr ffff00000f98ba38 by task binder-util/522

CPU: 4 UID: 0 PID: 522 Comm: binder-util Not tainted 6.19.0-rc6-00015-gc03e9c42ae8f #1 PREEMPT Hardware name: linux,dummy-virt (DT) Call trace: bindernetlinkreport.isra.0+0x694/0x6c8 bindertransaction+0x66e4/0x79b8 binderthreadwrite+0xab4/0x4440 binderioctl+0x1fd4/0x2940 [...]

Allocated by task 522: __kmalloccachenoprof+0x17c/0x50c bindertransaction+0x584/0x79b8 binderthreadwrite+0xab4/0x4440 binderioctl+0x1fd4/0x2940 [...]

Freed by task 488: kfree+0x1d0/0x420 binderfreetransaction+0x150/0x234 binderthreadread+0x2d08/0x3ce4 binder_ioctl+0x488/0x2940 [...] ==================================================================

Instead, make a transaction copy so the data can be safely accessed by bindernetlinkreport() after a pending frozen error. While here, add a comment about not using t->buffer in bindernetlinkreport().

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23184.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
63740349eba78f242bcbf60d5244d7f2b2600853
Fixed
a6050dedb6f1cc23e518e3a132ab74a0aad6df90
Fixed
5e8a3d01544282e50d887d76f30d1496a0a53562

Affected versions

v6.*
v6.17
v6.17-rc3
v6.17-rc4
v6.17-rc5
v6.17-rc6
v6.17-rc7
v6.18
v6.18-rc1
v6.18-rc2
v6.18-rc3
v6.18-rc4
v6.18-rc5
v6.18-rc6
v6.18-rc7
v6.18.1
v6.18.2
v6.18.3
v6.18.4
v6.18.5
v6.18.6
v6.18.7
v6.18.8
v6.18.9
v6.19-rc1
v6.19-rc2
v6.19-rc3
v6.19-rc4
v6.19-rc5
v6.19-rc6
v6.19-rc7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23184.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.18.0
Fixed
6.18.10

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-23184.json"