CVE-2026-64469

Source
https://cve.org/CVERecord?id=CVE-2026-64469
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64469.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-64469
Downstream
Related
Published
2026-07-25T08:51:34.025Z
Modified
2026-08-18T03:30:57.893786418Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
binder: fix UAF in binder_thread_release()
Details

In the Linux kernel, the following vulnerability has been resolved:

binder: fix UAF in binderthreadrelease()

When a thread exits, binderthreadrelease() walks its transaction stack to clear the t->from and t->toproc that correspond with the exiting thread. However, a process dying in parallel might attempt to kfree some of these transactions. And if one of them has no associated t->toproc, the t->toproc->innerlock will not be acquired.

This means that transaction accesses in binderthreadrelease() after t->toproc has been cleared might race with binderfree_transaction() and cause a use-after-free error as reported by KASAN:

================================================================== BUG: KASAN: slab-use-after-free in binderthreadrelease+0x5d0/0x798 Write of size 8 at addr ffff000016627500 by task X/715

CPU: 17 UID: 0 PID: 715 Comm: X Not tainted 7.1.0-rc5-00149-g8fde5d1d47f6 #30 PREEMPT Hardware name: linux,dummy-virt (DT) Call trace: binderthreadrelease+0x5d0/0x798 binder_ioctl+0x12c0/0x299c [...]

Allocated by task 717 on cpu 18 at 67.267803s: __kasan_kmalloc+0xa0/0xbc __kmalloccachenoprof+0x174/0x444 bindertransaction+0x554/0x8150 binderthreadwrite+0xa30/0x4354 binderioctl+0x20f0/0x299c [...]

Freed by task 202 on cpu 18 at 90.416221s: _kasanslabfree+0x58/0x80 kfree+0x1a0/0x4a4 binderfreetransaction+0x150/0x294 bindersendfailedreply+0x398/0x6d8 binderreleasework+0x3e4/0x4ec binderdeferredfunc+0xbd8/0x104c [...] ==================================================================

In order to avoid this, make sure that binderfreetransaction() reads the t->toproc under the transaction lock. This will serialize the transaction release with the accesses in binderthreadrelease(). Plus, it matches the documented locking rules for @toproc.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64469.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
7a4408c6bd3eb1dafba67986259191be081e3efb
Fixed
1f96f8c0a6ed4f6d01d3dd29ad0cbf08dde96082
Fixed
df1a17abba8d6fac5f965adcb8113ceace6e4949
Fixed
38e1a71728e5795b670cc159c18e286a40aeebb4
Fixed
faa070c7ad8ba25dcd0b12d7cdbb419e336f5391
Fixed
e63032dc715026a96bcaa13d375a8e15c91caa84
Fixed
ea02df466df60ecd758eb3b4df3f0cadc5c886ce
Fixed
ef5439ba5b9ac93349f5df12ef88b42a0ce26340
Fixed
114a116aaa5f0295376cdf12da743c5bce3b20ce

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64469.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.14.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.96
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.39
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64469.json"