CVE-2024-56556: binder: fix node UAF in binder_add_freeze_work()

Published Dec 27, 2024
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

binder: fix node UAF in binderaddfreezework()

In binderaddfreezework() we iterate over the proc->nodes with the proc->innerlock held. However, this lock is temporarily dropped in order to acquire the node->lock first (lock nesting order). This can race with bindernoderelease() and trigger a use-after-free:

================================================================== BUG: KASAN: slab-use-after-free in rawspinlock+0xe4/0x19c Write of size 4 at addr ffff53c04c29dd04 by task freeze/640

CPU: 5 UID: 0 PID: 640 Comm: freeze Not tainted 6.11.0-07343-ga727812a8d45 #17 Hardware name: linux,dummy-virt (DT) Call trace: rawspinlock+0xe4/0x19c binderaddfreezework+0x148/0x478 binderioctl+0x1e70/0x25ac arm64sysioctl+0x124/0x190

Allocated by task 637: kmalloccachenoprof+0x12c/0x27c bindernewnode+0x50/0x700 bindertransaction+0x35ac/0x6f74 binderthreadwrite+0xfb8/0x42a0 binderioctl+0x18f0/0x25ac arm64sysioctl+0x124/0x190

Freed by task 637: kfree+0xf0/0x330 binderthreadread+0x1e88/0x3a68 binderioctl+0x16d8/0x25ac arm64sysioctl+0x124/0x190 ==================================================================

Fix the race by taking a temporary reference on the node before releasing the proc->inner lock. This ensures the node remains alive while in use.

Affected Software

2 affected components
Linux Linux kernel>=6.12<6.12.4
Google Android

Event History

Dec 27, 2024
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
DescriptionSeverity
Apr 7, 2025
Data Sourced
via Android·12:00 AM
SeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-56556?

CVE-2024-56556 has not been assigned a specific CVSS score, but it is considered a significant vulnerability in the Linux kernel.

2

How do I fix CVE-2024-56556?

To fix CVE-2024-56556, update your Linux kernel to a version later than 6.12 or apply the relevant patches.

3

Who is affected by CVE-2024-56556?

CVE-2024-56556 affects users running certain versions of the Linux kernel, specifically those between 6.12 and 6.12.4.

4

What does CVE-2024-56556 exploit?

CVE-2024-56556 exploits a use-after-free (UAF) vulnerability in the binder component of the Linux kernel.

5

What are the implications of CVE-2024-56556?

The implications of CVE-2024-56556 can include system crashes or potential privilege escalation due to improper handling of memory in the Linux kernel.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203