CVE-2020-0423 is a use-after-free vulnerability in the binder_release_work function of binder.c in the Android kernel. The flaw is caused by improper locking, which allows a race condition where memory can be freed and subsequently accessed, leading to undefined behavior. This vulnerability can be exploited locally to escalate privileges within the kernel context, without requiring additional execution privileges or user interaction.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Small two-file repository containing a README and a single C proof-of-concept exploit for CVE-2020-0423, described as a Binder deferred work use-after-free. The code is standalone, not tied to a common exploit framework. The main file, exploit.c, defines Binder kernel structures and ioctl constants locally, then implements helper routines to open and mmap /dev/binder, become the Binder context manager, enter the looper state, send a crafted Binder transaction containing a flat_binder_object, read back transaction metadata to recover the kernel-managed transaction buffer pointer, and issue BC_FREE_BUFFER on that pointer. The exploit structure is race-oriented: main() creates a pipe for synchronization, forks, and splits execution into two cooperating processes. The child runs _ctx_manager_race(), pins itself to CPU 0, becomes the Binder context manager, waits for client activity, reads incoming Binder transactions to obtain the transaction buffer pointer, and then frees that buffer to trigger the vulnerable path. The parent runs _client_race(), pins itself to CPU 1, duplicates a Binder fd, sends an initial transaction to target handle 0 (the context manager) so the manager holds a binder_ref to the client's binder_node, then triggers the competing release path by issuing BINDER_THREAD_EXIT and closing the duplicated fd. This is intended to race binder_free_node against binder_release_work / binder_deferred_release. Capabilities: the exploit can repeatedly set up Binder IPC state, coordinate two processes across CPUs, create Binder references, parse Binder driver responses, and hammer the vulnerable race window in a loop. However, it is clearly a work-in-progress PoC: there is no post-exploitation stage, no arbitrary read/write primitive, no privilege escalation logic, and no shell or command payload. The only fingerprintable endpoint present is the local device file /dev/binder. Overall, this repository is a kernel-local race trigger PoC for Android's Binder subsystem rather than a complete weaponized exploit.
This repository contains a proof-of-concept (POC) exploit for CVE-2020-0423, a use-after-free (UAF) vulnerability in the Android binder driver. The main files are '2020-0423.c' and '2020-0423_spray1.c', which implement the logic to trigger the UAF condition by crafting and sending malicious binder transactions to the '/dev/binder' device. The exploit uses multiple threads and heap spraying techniques to increase the likelihood of triggering the race condition required for the UAF. The Makefile provides build instructions for Android (aarch64) targets, and 'run.sh' automates building, pushing, and executing the exploit on a connected Android device via adb. The README and debug logs document the process and kernel crash output (KASAN) confirming the bug is triggered. No weaponized payload is included; the exploit demonstrates the bug and causes a kernel crash, serving as a research tool for further exploitation development.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.