{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.180-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.96-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.4-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux-6.12"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.100-1~deb12u1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  binder: fix UAF in binder_thread_release()  When a thread exits, binder_thread_release() walks its transaction stack to clear the t-\u003efrom and t-\u003eto_proc that correspond with the exiting thread. However, a process dying in parallel might attempt to kfree some of these transactions. And if one of them has no associated t-\u003eto_proc, the t-\u003eto_proc-\u003einner_lock will not be acquired.  This means that transaction accesses in binder_thread_release() after t-\u003eto_proc has been cleared might race with binder_free_transaction() and cause a use-after-free error as reported by KASAN:    ==================================================================   BUG: KASAN: slab-use-after-free in binder_thread_release+0x5d0/0x798   Write of size 8 at addr ffff000016627500 by task X/715    CPU: 17 UID: 0 PID: 715 Comm: X Not tainted 7.1.0-rc5-00149-g8fde5d1d47f6 #30 PREEMPT   Hardware name: linux,dummy-virt (DT)   Call trace:    binder_thread_release+0x5d0/0x798    binder_ioctl+0x12c0/0x299c    [...]    Allocated by task 717 on cpu 18 at 67.267803s:    __kasan_kmalloc+0xa0/0xbc    __kmalloc_cache_noprof+0x174/0x444    binder_transaction+0x554/0x8150    binder_thread_write+0xa30/0x4354    binder_ioctl+0x20f0/0x299c    [...]    Freed by task 202 on cpu 18 at 90.416221s:    __kasan_slab_free+0x58/0x80    kfree+0x1a0/0x4a4    binder_free_transaction+0x150/0x294    binder_send_failed_reply+0x398/0x6d8    binder_release_work+0x3e4/0x4ec    binder_deferred_func+0xbd8/0x104c    [...]   ==================================================================  In order to avoid this, make sure that binder_free_transaction() reads the t-\u003eto_proc under the transaction lock. This will serialize the transaction release with the accesses in binder_thread_release(). Plus, it matches the documented locking rules for @to_proc.",
  "id": "DEBIAN-CVE-2026-64469",
  "modified": "2026-09-14T16:47:50.288615416Z",
  "published": "2026-07-25T10:17:32.247Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-64469"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-64469"
  ]
}