Use-after-free in Linux kernel - CVE-2026-64469
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a use-after-free in binder_thread_release() when releasing binder threads while transactions are being freed in parallel. A local user can trigger concurrent binder transaction activity to cause a denial of service.
The issue is caused by a race condition involving transaction stack cleanup during thread exit and parallel process teardown.
Affected software
How to mitigate CVE-2026-64469
External References
- https://git.kernel.org/stable/c/114a116aaa5f0295376cdf12da743c5bce3b20ce
- https://git.kernel.org/stable/c/1f96f8c0a6ed4f6d01d3dd29ad0cbf08dde96082
- https://git.kernel.org/stable/c/38e1a71728e5795b670cc159c18e286a40aeebb4
- https://git.kernel.org/stable/c/df1a17abba8d6fac5f965adcb8113ceace6e4949
- https://git.kernel.org/stable/c/e63032dc715026a96bcaa13d375a8e15c91caa84
- https://git.kernel.org/stable/c/ea02df466df60ecd758eb3b4df3f0cadc5c886ce
- https://git.kernel.org/stable/c/ef5439ba5b9ac93349f5df12ef88b42a0ce26340
- https://git.kernel.org/stable/c/faa070c7ad8ba25dcd0b12d7cdbb419e336f5391