PT-2026-8192 · Linux · Linux Kernel
CVE-2026-23184
·
Published
2026-01-01
·
Updated
2026-02-19
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.19.0-rc6-00015-gc03e9c42ae8f
Description
The Linux kernel contains a use-after-free issue within the binder subsystem, specifically in the
binder netlink report() function. Oneway transactions sent to frozen targets can return a BR TRANSACTION PENDING FROZEN error, but are incorrectly treated as successful. This allows for unsafe access to transaction data ('t') after the error, potentially leading to a crash. The issue was identified through a KASAN report indicating a slab-use-after-free condition. The fix involves creating a transaction copy to ensure safe data access by binder netlink report() following a pending frozen error. The vulnerable function is binder netlink report().Recommendations
Update to Linux kernel version 6.19.0-rc6-00015-gc03e9c42ae8f or a later version to address this issue.
Exploit
Fix
Use After Free
Improper Check for Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel