{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-64468",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2026-07-19T15:36:31.790Z",
        "datePublished": "2026-07-25T08:51:33.364Z",
        "dateUpdated": "2026-08-17T04:56:13.826Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-17T04:56:13.826Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nbinder: fix UAF in binder_free_transaction()\n\nIn binder_free_transaction(), the t->to_proc is read under the t->lock.\nHowever, once the t->lock is dropped, the to_proc can die in parallel.\nThis leads to a use-after-free error when we attempt to acquire its\ninner lock right afterwards:\n\n  ==================================================================\n  BUG: KASAN: slab-use-after-free in _raw_spin_lock+0xe4/0x1a0\n  Write of size 4 at addr ffff00001125da70 by task B/672\n\n  CPU: 20 UID: 0 PID: 672 Comm: B Not tainted 7.1.0-rc6-00284-g8e65320d91cd #4 PREEMPT\n  Hardware name: linux,dummy-virt (DT)\n  Call trace:\n   _raw_spin_lock+0xe4/0x1a0\n   binder_free_transaction+0x8c/0x320\n   binder_send_failed_reply+0x21c/0x2f8\n   binder_thread_release+0x488/0x7e0\n   binder_ioctl+0x12c0/0x29a0\n  [...]\n\n  Allocated by task 675:\n   __kmalloc_cache_noprof+0x174/0x444\n   binder_open+0x118/0xb70\n   do_dentry_open+0x374/0x1040\n   vfs_open+0x58/0x3bc\n  [...]\n\n  Freed by task 212:\n   __kasan_slab_free+0x58/0x80\n   kfree+0x1a0/0x4a4\n   binder_proc_dec_tmpref+0x32c/0x5e0\n   binder_deferred_func+0xc48/0x104c\n   process_one_work+0x53c/0xbc0\n  [...]\n  ==================================================================\n\nTo prevent this, pin the target thread (t->to_thread) to guarantee the\ntarget process remains alive. Undelivered transactions without a target\nthread are already safe, as the target process can only be the current\ncontext in those paths."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The vulnerability is reached through Binder device ioctls, including BINDER_WRITE_READ and BINDER_THREAD_EXIT, so the attacker requires local execution.\nAC:L - Attacker-controlled processes can construct the transaction stack and concurrently trigger both thread and target-process teardown, allowing repeated race attempts and heap spraying.\nPR:L - A basic unprivileged user can access an available Binder device or mount a private BinderFS instance through a user namespace; no capability in the initial user namespace is required.\nUI:N - All required transactions, thread exits, and process teardown can be performed by attacker-controlled processes without victim action.\nS:U - Exploitation affects the host kernel within its existing security authority, making this a standard local kernel privilege escalation with unchanged scope.\nC:H - The freed binder_proc can be reclaimed with attacker-influenced data, and subsequent stale-pointer dereferences can provide kernel-memory access and disclosure primitives.\nI:H - The UAF performs spinlock and counter writes into freed slab memory and may operate on a reclaimed waitqueue, enabling heap corruption and potential arbitrary kernel code execution.\nA:H - The demonstrated invalid spinlock write causes a KASAN UAF, and exploitation can otherwise produce a kernel crash, panic, or hang."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/android/binder.c"
                    ],
                    "versions": [
                        {
                            "version": "a370003cc301d4361bae20c9ef615f89bf8d1e8a",
                            "lessThan": "5602a43f251c3d75312df91a422675fc00ca3dce",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "a370003cc301d4361bae20c9ef615f89bf8d1e8a",
                            "lessThan": "0be901ab1dcc4af59b88f2e324493bb283850167",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "a370003cc301d4361bae20c9ef615f89bf8d1e8a",
                            "lessThan": "48aeda9f8039e4a6971d1804578efde7f2c01eda",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "a370003cc301d4361bae20c9ef615f89bf8d1e8a",
                            "lessThan": "45df558c543bb5543bacc8065fd7c567740781e5",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "a370003cc301d4361bae20c9ef615f89bf8d1e8a",
                            "lessThan": "d45ef513eed1abebfec90c3cfb6ae50c2a4182db",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "a370003cc301d4361bae20c9ef615f89bf8d1e8a",
                            "lessThan": "328ccf32acb87e8bbb1fe2b065068c574e4db2bf",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "a370003cc301d4361bae20c9ef615f89bf8d1e8a",
                            "lessThan": "0f15f0f6ca5df566275ce517f257af2559528b41",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "a370003cc301d4361bae20c9ef615f89bf8d1e8a",
                            "lessThan": "f223d27a546c1e1f48d38fd67760e78f068fe8c4",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "a4a3c070b8760f71c8311399fa9bfe67c8629bca",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "22068d49d09d2b3890e19d7b2048a33340f992da",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "0e3b977a8f1be01dcfa0baae68851b1f55f2a0a9",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "4.14.136",
                            "lessThan": "4.15",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "4.19.64",
                            "lessThan": "4.20",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.1.15",
                            "lessThan": "5.2",
                            "status": "affected",
                            "versionType": "semver"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/android/binder.c"
                    ],
                    "versions": [
                        {
                            "version": "5.2",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "5.2",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.10.261",
                            "lessThanOrEqual": "5.10.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.15.212",
                            "lessThanOrEqual": "5.15.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.178",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.145",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.96",
                            "lessThanOrEqual": "6.12.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.18.39",
                            "lessThanOrEqual": "6.18.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.1.4",
                            "lessThanOrEqual": "7.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.2",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.2",
                                    "versionEndExcluding": "5.10.261"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.2",
                                    "versionEndExcluding": "5.15.212"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.2",
                                    "versionEndExcluding": "6.1.178"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.2",
                                    "versionEndExcluding": "6.6.145"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.2",
                                    "versionEndExcluding": "6.12.96"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.2",
                                    "versionEndExcluding": "6.18.39"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.2",
                                    "versionEndExcluding": "7.1.4"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.2",
                                    "versionEndExcluding": "7.2"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.14.136"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.19.64"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.1.15"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/5602a43f251c3d75312df91a422675fc00ca3dce"
                },
                {
                    "url": "https://git.kernel.org/stable/c/0be901ab1dcc4af59b88f2e324493bb283850167"
                },
                {
                    "url": "https://git.kernel.org/stable/c/48aeda9f8039e4a6971d1804578efde7f2c01eda"
                },
                {
                    "url": "https://git.kernel.org/stable/c/45df558c543bb5543bacc8065fd7c567740781e5"
                },
                {
                    "url": "https://git.kernel.org/stable/c/d45ef513eed1abebfec90c3cfb6ae50c2a4182db"
                },
                {
                    "url": "https://git.kernel.org/stable/c/328ccf32acb87e8bbb1fe2b065068c574e4db2bf"
                },
                {
                    "url": "https://git.kernel.org/stable/c/0f15f0f6ca5df566275ce517f257af2559528b41"
                },
                {
                    "url": "https://git.kernel.org/stable/c/f223d27a546c1e1f48d38fd67760e78f068fe8c4"
                }
            ],
            "title": "binder: fix UAF in binder_free_transaction()",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}