CVE-2026-64468

Description

A flaw was found in the Linux kernel's binder component. A use-after-free (UAF) vulnerability exists in the binder_free_transaction() function, where a process's reference is accessed after the lock protecting it is released, allowing the process to terminate prematurely. A local attacker with low privileges could exploit this to cause a system crash (denial of service) or potentially gain elevated privileges.

Understanding the Weakness (CWE)

Integrity,Other

Technical Impact: Alter Execution Logic; Unexpected State

The main problem is that -- if a lock is overcome -- data could be altered in a bad state.

Frequently Asked Questions

Want to get errata notifications? Sign up here.