Use-after-free in Linux kernel - CVE-2026-64468

 

Use-after-free in Linux kernel - CVE-2026-64468

Published: July 27, 2026


Vulnerability identifier: #VU139464
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-64468
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to use-after-free in binder_free_transaction() when freeing binder transactions. A local user can trigger a race condition involving a binder transaction to cause a denial of service.

The issue occurs because the target process can be freed after its reference is read and before its inner lock is acquired.


Affected software

Linux kernel

How to mitigate CVE-2026-64468

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins