Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-64468

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
25/07/2026
Última modificación:
25/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> binder: fix UAF in binder_free_transaction()<br /> <br /> In binder_free_transaction(), the t-&gt;to_proc is read under the t-&gt;lock.<br /> However, once the t-&gt;lock is dropped, the to_proc can die in parallel.<br /> This leads to a use-after-free error when we attempt to acquire its<br /> inner lock right afterwards:<br /> <br /> ==================================================================<br /> BUG: KASAN: slab-use-after-free in _raw_spin_lock+0xe4/0x1a0<br /> Write of size 4 at addr ffff00001125da70 by task B/672<br /> <br /> CPU: 20 UID: 0 PID: 672 Comm: B Not tainted 7.1.0-rc6-00284-g8e65320d91cd #4 PREEMPT<br /> Hardware name: linux,dummy-virt (DT)<br /> Call trace:<br /> _raw_spin_lock+0xe4/0x1a0<br /> binder_free_transaction+0x8c/0x320<br /> binder_send_failed_reply+0x21c/0x2f8<br /> binder_thread_release+0x488/0x7e0<br /> binder_ioctl+0x12c0/0x29a0<br /> [...]<br /> <br /> Allocated by task 675:<br /> __kmalloc_cache_noprof+0x174/0x444<br /> binder_open+0x118/0xb70<br /> do_dentry_open+0x374/0x1040<br /> vfs_open+0x58/0x3bc<br /> [...]<br /> <br /> Freed by task 212:<br /> __kasan_slab_free+0x58/0x80<br /> kfree+0x1a0/0x4a4<br /> binder_proc_dec_tmpref+0x32c/0x5e0<br /> binder_deferred_func+0xc48/0x104c<br /> process_one_work+0x53c/0xbc0<br /> [...]<br /> ==================================================================<br /> <br /> To prevent this, pin the target thread (t-&gt;to_thread) to guarantee the<br /> target process remains alive. Undelivered transactions without a target<br /> thread are already safe, as the target process can only be the current<br /> context in those paths.

Impacto