SB2026072787 - Use-after-free in Linux kernel android driver
Published: July 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-64469)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in binder_thread_release() when releasing binder threads while transactions are being freed in parallel. A local user can trigger concurrent binder transaction activity to cause a denial of service.
The issue is caused by a race condition involving transaction stack cleanup during thread exit and parallel process teardown.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/114a116aaa5f0295376cdf12da743c5bce3b20ce
- https://git.kernel.org/stable/c/1f96f8c0a6ed4f6d01d3dd29ad0cbf08dde96082
- https://git.kernel.org/stable/c/38e1a71728e5795b670cc159c18e286a40aeebb4
- https://git.kernel.org/stable/c/df1a17abba8d6fac5f965adcb8113ceace6e4949
- https://git.kernel.org/stable/c/e63032dc715026a96bcaa13d375a8e15c91caa84
- https://git.kernel.org/stable/c/ea02df466df60ecd758eb3b4df3f0cadc5c886ce
- https://git.kernel.org/stable/c/ef5439ba5b9ac93349f5df12ef88b42a0ce26340
- https://git.kernel.org/stable/c/faa070c7ad8ba25dcd0b12d7cdbb419e336f5391