{"api_version":"1","generated_at":"2026-08-02T08:27:40+00:00","cve":"CVE-2026-64468","urls":{"html":"https://cve.report/CVE-2026-64468","api":"https://cve.report/api/cve/CVE-2026-64468.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-64468","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-64468"},"summary":{"title":"binder: fix UAF in binder_free_transaction()","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbinder: fix UAF in binder_free_transaction()\n\nIn binder_free_transaction(), the t->to_proc is read under the t->lock.\nHowever, once the t->lock is dropped, the to_proc can die in parallel.\nThis leads to a use-after-free error when we attempt to acquire its\ninner lock right afterwards:\n\n  ==================================================================\n  BUG: KASAN: slab-use-after-free in _raw_spin_lock+0xe4/0x1a0\n  Write of size 4 at addr ffff00001125da70 by task B/672\n\n  CPU: 20 UID: 0 PID: 672 Comm: B Not tainted 7.1.0-rc6-00284-g8e65320d91cd #4 PREEMPT\n  Hardware name: linux,dummy-virt (DT)\n  Call trace:\n   _raw_spin_lock+0xe4/0x1a0\n   binder_free_transaction+0x8c/0x320\n   binder_send_failed_reply+0x21c/0x2f8\n   binder_thread_release+0x488/0x7e0\n   binder_ioctl+0x12c0/0x29a0\n  [...]\n\n  Allocated by task 675:\n   __kmalloc_cache_noprof+0x174/0x444\n   binder_open+0x118/0xb70\n   do_dentry_open+0x374/0x1040\n   vfs_open+0x58/0x3bc\n  [...]\n\n  Freed by task 212:\n   __kasan_slab_free+0x58/0x80\n   kfree+0x1a0/0x4a4\n   binder_proc_dec_tmpref+0x32c/0x5e0\n   binder_deferred_func+0xc48/0x104c\n   process_one_work+0x53c/0xbc0\n  [...]\n  ==================================================================\n\nTo prevent this, pin the target thread (t->to_thread) to guarantee the\ntarget process remains alive. Undelivered transactions without a target\nthread are already safe, as the target process can only be the current\ncontext in those paths.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-07-25 10:17:32","updated_at":"2026-07-27 05:16:52"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/5602a43f251c3d75312df91a422675fc00ca3dce","name":"https://git.kernel.org/stable/c/5602a43f251c3d75312df91a422675fc00ca3dce","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/0f15f0f6ca5df566275ce517f257af2559528b41","name":"https://git.kernel.org/stable/c/0f15f0f6ca5df566275ce517f257af2559528b41","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/0be901ab1dcc4af59b88f2e324493bb283850167","name":"https://git.kernel.org/stable/c/0be901ab1dcc4af59b88f2e324493bb283850167","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/48aeda9f8039e4a6971d1804578efde7f2c01eda","name":"https://git.kernel.org/stable/c/48aeda9f8039e4a6971d1804578efde7f2c01eda","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/45df558c543bb5543bacc8065fd7c567740781e5","name":"https://git.kernel.org/stable/c/45df558c543bb5543bacc8065fd7c567740781e5","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/328ccf32acb87e8bbb1fe2b065068c574e4db2bf","name":"https://git.kernel.org/stable/c/328ccf32acb87e8bbb1fe2b065068c574e4db2bf","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/f223d27a546c1e1f48d38fd67760e78f068fe8c4","name":"https://git.kernel.org/stable/c/f223d27a546c1e1f48d38fd67760e78f068fe8c4","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/d45ef513eed1abebfec90c3cfb6ae50c2a4182db","name":"https://git.kernel.org/stable/c/d45ef513eed1abebfec90c3cfb6ae50c2a4182db","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-64468","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64468","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected a370003cc301d4361bae20c9ef615f89bf8d1e8a 5602a43f251c3d75312df91a422675fc00ca3dce git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected a370003cc301d4361bae20c9ef615f89bf8d1e8a 0be901ab1dcc4af59b88f2e324493bb283850167 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected a370003cc301d4361bae20c9ef615f89bf8d1e8a 48aeda9f8039e4a6971d1804578efde7f2c01eda git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected a370003cc301d4361bae20c9ef615f89bf8d1e8a 45df558c543bb5543bacc8065fd7c567740781e5 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected a370003cc301d4361bae20c9ef615f89bf8d1e8a d45ef513eed1abebfec90c3cfb6ae50c2a4182db git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected a370003cc301d4361bae20c9ef615f89bf8d1e8a 328ccf32acb87e8bbb1fe2b065068c574e4db2bf git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected a370003cc301d4361bae20c9ef615f89bf8d1e8a 0f15f0f6ca5df566275ce517f257af2559528b41 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected a370003cc301d4361bae20c9ef615f89bf8d1e8a f223d27a546c1e1f48d38fd67760e78f068fe8c4 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected a4a3c070b8760f71c8311399fa9bfe67c8629bca git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 22068d49d09d2b3890e19d7b2048a33340f992da git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 0e3b977a8f1be01dcfa0baae68851b1f55f2a0a9 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4.14.136 4.15 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4.19.64 4.20 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.1.15 5.2 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.2","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.2 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.10.261 5.10.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.212 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.178 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.145 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.96 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.39 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.4 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2-rc3 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"64468","cve":"CVE-2026-64468","epss":"0.001350000","percentile":"0.033620000","score_date":"2026-07-29","updated_at":"2026-07-30 00:09:16"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/android/binder.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"5602a43f251c3d75312df91a422675fc00ca3dce","status":"affected","version":"a370003cc301d4361bae20c9ef615f89bf8d1e8a","versionType":"git"},{"lessThan":"0be901ab1dcc4af59b88f2e324493bb283850167","status":"affected","version":"a370003cc301d4361bae20c9ef615f89bf8d1e8a","versionType":"git"},{"lessThan":"48aeda9f8039e4a6971d1804578efde7f2c01eda","status":"affected","version":"a370003cc301d4361bae20c9ef615f89bf8d1e8a","versionType":"git"},{"lessThan":"45df558c543bb5543bacc8065fd7c567740781e5","status":"affected","version":"a370003cc301d4361bae20c9ef615f89bf8d1e8a","versionType":"git"},{"lessThan":"d45ef513eed1abebfec90c3cfb6ae50c2a4182db","status":"affected","version":"a370003cc301d4361bae20c9ef615f89bf8d1e8a","versionType":"git"},{"lessThan":"328ccf32acb87e8bbb1fe2b065068c574e4db2bf","status":"affected","version":"a370003cc301d4361bae20c9ef615f89bf8d1e8a","versionType":"git"},{"lessThan":"0f15f0f6ca5df566275ce517f257af2559528b41","status":"affected","version":"a370003cc301d4361bae20c9ef615f89bf8d1e8a","versionType":"git"},{"lessThan":"f223d27a546c1e1f48d38fd67760e78f068fe8c4","status":"affected","version":"a370003cc301d4361bae20c9ef615f89bf8d1e8a","versionType":"git"},{"status":"affected","version":"a4a3c070b8760f71c8311399fa9bfe67c8629bca","versionType":"git"},{"status":"affected","version":"22068d49d09d2b3890e19d7b2048a33340f992da","versionType":"git"},{"status":"affected","version":"0e3b977a8f1be01dcfa0baae68851b1f55f2a0a9","versionType":"git"},{"lessThan":"4.15","status":"affected","version":"4.14.136","versionType":"semver"},{"lessThan":"4.20","status":"affected","version":"4.19.64","versionType":"semver"},{"lessThan":"5.2","status":"affected","version":"5.1.15","versionType":"semver"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/android/binder.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"5.2"},{"lessThan":"5.2","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.261","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.212","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.178","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.145","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.96","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.39","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.4","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2-rc3","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.261","versionStartIncluding":"5.2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.212","versionStartIncluding":"5.2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.178","versionStartIncluding":"5.2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.145","versionStartIncluding":"5.2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.96","versionStartIncluding":"5.2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.39","versionStartIncluding":"5.2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.4","versionStartIncluding":"5.2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2-rc3","versionStartIncluding":"5.2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.14.136","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.19.64","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.1.15","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nbinder: fix UAF in binder_free_transaction()\n\nIn binder_free_transaction(), the t->to_proc is read under the t->lock.\nHowever, once the t->lock is dropped, the to_proc can die in parallel.\nThis leads to a use-after-free error when we attempt to acquire its\ninner lock right afterwards:\n\n  ==================================================================\n  BUG: KASAN: slab-use-after-free in _raw_spin_lock+0xe4/0x1a0\n  Write of size 4 at addr ffff00001125da70 by task B/672\n\n  CPU: 20 UID: 0 PID: 672 Comm: B Not tainted 7.1.0-rc6-00284-g8e65320d91cd #4 PREEMPT\n  Hardware name: linux,dummy-virt (DT)\n  Call trace:\n   _raw_spin_lock+0xe4/0x1a0\n   binder_free_transaction+0x8c/0x320\n   binder_send_failed_reply+0x21c/0x2f8\n   binder_thread_release+0x488/0x7e0\n   binder_ioctl+0x12c0/0x29a0\n  [...]\n\n  Allocated by task 675:\n   __kmalloc_cache_noprof+0x174/0x444\n   binder_open+0x118/0xb70\n   do_dentry_open+0x374/0x1040\n   vfs_open+0x58/0x3bc\n  [...]\n\n  Freed by task 212:\n   __kasan_slab_free+0x58/0x80\n   kfree+0x1a0/0x4a4\n   binder_proc_dec_tmpref+0x32c/0x5e0\n   binder_deferred_func+0xc48/0x104c\n   process_one_work+0x53c/0xbc0\n  [...]\n  ==================================================================\n\nTo prevent this, pin the target thread (t->to_thread) to guarantee the\ntarget process remains alive. Undelivered transactions without a target\nthread are already safe, as the target process can only be the current\ncontext in those paths."}],"metrics":[{"cvssV3_1":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"providerMetadata":{"dateUpdated":"2026-07-27T05:01:22.679Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/5602a43f251c3d75312df91a422675fc00ca3dce"},{"url":"https://git.kernel.org/stable/c/0be901ab1dcc4af59b88f2e324493bb283850167"},{"url":"https://git.kernel.org/stable/c/48aeda9f8039e4a6971d1804578efde7f2c01eda"},{"url":"https://git.kernel.org/stable/c/45df558c543bb5543bacc8065fd7c567740781e5"},{"url":"https://git.kernel.org/stable/c/d45ef513eed1abebfec90c3cfb6ae50c2a4182db"},{"url":"https://git.kernel.org/stable/c/328ccf32acb87e8bbb1fe2b065068c574e4db2bf"},{"url":"https://git.kernel.org/stable/c/0f15f0f6ca5df566275ce517f257af2559528b41"},{"url":"https://git.kernel.org/stable/c/f223d27a546c1e1f48d38fd67760e78f068fe8c4"}],"title":"binder: fix UAF in binder_free_transaction()","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-64468","datePublished":"2026-07-25T08:51:33.364Z","dateReserved":"2026-07-19T15:36:31.790Z","dateUpdated":"2026-07-27T05:01:22.679Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-25 10:17:32","lastModifiedDate":"2026-07-27 05:16:52","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"64468","Ordinal":"1","Title":"binder: fix UAF in binder_free_transaction()","CVE":"CVE-2026-64468","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"64468","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nbinder: fix UAF in binder_free_transaction()\n\nIn binder_free_transaction(), the t->to_proc is read under the t->lock.\nHowever, once the t->lock is dropped, the to_proc can die in parallel.\nThis leads to a use-after-free error when we attempt to acquire its\ninner lock right afterwards:\n\n  ==================================================================\n  BUG: KASAN: slab-use-after-free in _raw_spin_lock+0xe4/0x1a0\n  Write of size 4 at addr ffff00001125da70 by task B/672\n\n  CPU: 20 UID: 0 PID: 672 Comm: B Not tainted 7.1.0-rc6-00284-g8e65320d91cd #4 PREEMPT\n  Hardware name: linux,dummy-virt (DT)\n  Call trace:\n   _raw_spin_lock+0xe4/0x1a0\n   binder_free_transaction+0x8c/0x320\n   binder_send_failed_reply+0x21c/0x2f8\n   binder_thread_release+0x488/0x7e0\n   binder_ioctl+0x12c0/0x29a0\n  [...]\n\n  Allocated by task 675:\n   __kmalloc_cache_noprof+0x174/0x444\n   binder_open+0x118/0xb70\n   do_dentry_open+0x374/0x1040\n   vfs_open+0x58/0x3bc\n  [...]\n\n  Freed by task 212:\n   __kasan_slab_free+0x58/0x80\n   kfree+0x1a0/0x4a4\n   binder_proc_dec_tmpref+0x32c/0x5e0\n   binder_deferred_func+0xc48/0x104c\n   process_one_work+0x53c/0xbc0\n  [...]\n  ==================================================================\n\nTo prevent this, pin the target thread (t->to_thread) to guarantee the\ntarget process remains alive. Undelivered transactions without a target\nthread are already safe, as the target process can only be the current\ncontext in those paths.","Type":"Description","Title":"binder: fix UAF in binder_free_transaction()"}]}}}