CVE-2023-20938 is a use-after-free vulnerability in the Android kernel Binder driver, specifically in binder_transaction_buffer_release in binder.c. The flaw is caused by improper input validation that can result in memory being accessed after it has been freed. On affected Android devices, successful exploitation can allow a local attacker to trigger kernel memory corruption and elevate privileges. The issue affects Android kernel components and was addressed in Android's February 2023 security updates.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
6 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a C-based local kernel PoC for CVE-2023-20938 targeting Android's Binder subsystem. It is not part of a larger exploit framework. The codebase is structured as a small Binder/HwBinder userspace toolkit plus a PoC driver program. Core files include binder.c/binder.h for low-level Binder device interaction, hwbinder.c/hwbinder.h for HIDL/HwBinder service discovery and token-manager interaction, utils.c/utils.h for helper routines, uapi_binder.h for Binder UAPI definitions, and poc.c as the main trigger logic. The Makefile builds a static binary named 'aapk'. Main capability: the PoC orchestrates Binder transactions between cooperating contexts to trigger a use-after-free in the kernel Binder driver. In poc.c, the parent thread obtains a Binder handle associated with a token created by the child via ITokenManager over /dev/hwbinder. The child enters a Binder looper and, upon receiving a Binder object handle, calls free_binder_node(), which sends two crafted Binder transactions: one normal transaction carrying a flat_binder_object and a second malformed transaction with an intentionally misaligned offsets_size (sizeof(offsets2) - 1). This matches the README’s vulnerability description: the malformed transaction drives the kernel into an error path where binder_transaction_buffer_release operates on an incompletely initialized state, contributing to incorrect node reference handling and eventual freeing of a Binder node that is later referenced again. The exploit is a proof-of-concept crash trigger, not a full privilege-escalation exploit. There is no post-exploitation payload, shell, network callback, persistence, or data exfiltration logic. The provided result is a kernel KASAN use-after-free report in binder_ioctl/binder_thread_read paths. The README explicitly states the exploit is still under development ('TODO: exploit编写中...'), which supports classifying it as POC maturity. Fingerprintable targets/endpoints are entirely local: /dev/binder and /dev/hwbinder device nodes, plus the HIDL service identifiers android.hidl.manager@1.0::IServiceManager and android.hidl.token@1.0::ITokenManager. No external IPs, domains, or HTTP(S) endpoints are contacted. Overall, the repository’s purpose is to reproduce and study the Binder UAF condition behind CVE-2023-20938 in a controlled Android test environment.
Repository contains a standalone C proof-of-concept exploit for CVE-2023-20938, an Android Binder driver use-after-free in binder_transaction_buffer_release(). Structure is minimal: README.md documents the bug, target environment, build/run steps, and exploitation stages; binder.h provides Binder UAPI definitions; poc_cf.c is the main exploit implementation. The exploit is not part of a larger framework. The PoC is a real local privilege-escalation exploit, not a detector. It targets a specific vulnerable Android emulator/test environment: Cuttlefish/Goldfish AVD on x86_64 with kernel 5.10.107. The code uses two unprivileged processes and HwBinder/ITokenManager to share a Binder node, then triggers the Binder UAF by crafting a transaction with a malformed offsets_size. From there it performs a staged exploitation chain: reclaiming freed binder_node objects with eventpoll epitems for a cross-cache kernel pointer leak; re-triggering the UAF with fake binder_node data to convert Binder unlink behavior into controlled kernel writes; using those writes to redirect a file's f_inode and obtain a steerable 4-byte arbitrary read via FIGETBSZ; leaking kernel pointers to defeat KASLR; walking init_task to locate the launcher process credentials; zeroing uid/gid-related cred fields and seccomp.mode; zeroing selinux_state to force SELinux permissive; and finally spawning /system/bin/sh as a root shell. Notable fingerprintable targets are local device/service endpoints rather than remote network infrastructure: /dev/hwbinder, the HIDL service names android.hidl.manager@1.0::IServiceManager and android.hidl.token@1.0::ITokenManager, and /system/bin/sh. The README also references the example execution path /data/local/tmp/poc_cf and vulnerable boot artifacts bzImage and initramfs.img. Overall, this is an operational, build-specific Android kernel LPE PoC with a hardcoded post-exploitation outcome of root shell access.
This repository is a research/exploit project for Android Binder/HwBinder internals centered on CVE-2023-20938, a use-after-free in binder_transaction_buffer_release. It is not just documentation: the exploit/ directory contains a standalone C exploit that opens /dev/hwbinder, manually constructs raw Binder/HwBinder ioctl payloads, resolves android.hidl.token@1.0::ITokenManager through android.hidl.manager@1.0::IServiceManager, creates or retrieves a token-backed binder object, and then sends malformed one-way Binder transactions intended to trigger the vulnerable kernel path. Repository structure is mixed: (1) extensive Markdown notes explaining Binder internals, vulnerability root cause, exploitation strategy, and HIDL parcel construction; (2) generated HIDL artifacts under hidl_gen/ for IServiceManager and ITokenManager, used as references for transaction layout and method numbering; (3) exploit/ C sources implementing raw Binder/HwBinder helpers and the UAF trigger; and (4) nativeBinder/, an Android app/NDK test harness that creates a native binder service and experiments with obtaining binder handles from Java/NDK objects. Main exploit flow in exploit/main.c: open /dev/hwbinder via hwbinder_open; resolve ITokenManager handle using find_tokenManager with interface token android.hidl.manager@1.0::IServiceManager and instance "default"; create a token for a dummy binder value (0xdeadbeef) using create_token; fork a child thread/process path that retrieves a handle associated with that token (via anansi_get / related helper paths in hwbinder.c); then call trigger_uaf in exploit/binder.c. The trigger sends BC_TRANSACTION messages with flat_binder_object payloads and deliberately malformed offsets_size values of sizeof(offsets)-1, matching the repository notes that the bug is reachable when buffer/offset validation fails on misaligned offsets. The exploit is therefore a local kernel memory corruption trigger rather than a complete end-to-end root exploit. Notable capabilities: raw ioctl-based Binder and HwBinder communication; manual HIDL parcel marshalling using BINDER_TYPE_PTR scatter-gather objects; service discovery through IServiceManager; token-based binder object exchange through ITokenManager; binder handle acquisition and reference manipulation (BC_ACQUIRE, BC_FREE_BUFFER); and a concrete malformed transaction sequence to hit the vulnerable release path. The Android app in nativeBinder/ is auxiliary research tooling, not the primary exploit, and demonstrates creating a native binder service, checking Binder accessibility, and attempting to derive a kernel binder handle from a Java IBinder object. No external C2 or remote network exploitation is present. The attack vector is strictly local against Android Binder/HwBinder kernel interfaces and system HIDL services.
Repository purpose: a bug trigger/PoC for CVE-2023-20938 in Android's Binder driver, with two main tracks: 1) libdevbinder/ (QEMU/emulation path) - Bundles a full Binder interaction library (Google's libdevbinder) plus example programs that implement a two-process Binder interaction pattern. - libdevbinder/examples/server.c: sets itself as Binder context manager (binder_set_context_manager), receives an initial transaction, then runs stage_1 and stage_2. stage_1 acquires a handle from an incoming flat_binder_object and performs a heap spray pattern by sending many raw transactions of different sizes (24 and 8 bytes) and receiving replies, then frees the original transaction buffer. stage_2 collects many handles (NUM_NODES) and then calls binder_send_exp() against each handle in reverse order; binder_send_exp() intentionally sets offsets_size to (real_offsets_size + 1), i.e., malformed metadata likely intended to trigger the CVE. - libdevbinder/examples/client.c: connects to /dev/binder, enters looper, sends an initial one-way transaction containing a binder object, then waits for ROUND_1_SPRAY incoming transactions, records their buffer pointers, and frees alternating buffers to shape heap state; then sends many one-way transactions with binder objects to create nodes/handles. - libdevbinder/src/exp.c: additional experimental trigger code using clone(CLONE_FILES) and binder_client_init; opens /dev/binder and sends a one-way transaction with a weak binder object. 2) src/ (real device path) - src/main.c is the primary entry point for the on-device trigger. It uses clone() to create two threads/processes sharing VM/files (CLONE_VM|CLONE_FILES) and coordinates with a shared mmap() barrier. - child_thread_a: opens /dev/hwbinder, publishes a handle under name "l33t" (via binder_lookup helpers that talk to TokenManager), then later unregisters it, enters looper, and calls recv_exploit_ref() to parse a received binder object/handle from raw binder read data. It then sends multiple transactions to the obtained handle, including a final binder_send_exp() call (malformed offsets_size) to trigger the bug, then releases the handle. - child_thread_b: waits for barrier, opens /dev/hwbinder, grabs the handle for "l33t", and sends a one-way transaction containing a binder object. - src/binder_lookup.c implements HIDL TokenManager-based publish/grab/unregister primitives by crafting BC_TRANSACTION_SG messages to the hardware service manager and token manager (interface tokens: android.hidl.manager@1.0::IServiceManager and android.hidl.token@1.0::ITokenManager). Exploit capabilities (as implemented): - Local kernel attack via Binder/HwBinder device nodes. - Heap shaping via Binder buffer spray/free patterns (notably in libdevbinder examples). - Handle lifecycle manipulation (acquire/release) and service-name based handle exchange using HIDL TokenManager. - Malformed Binder transaction construction (binder_send_exp adds +1 to offsets_size) consistent with triggering a kernel-side bounds/validation bug. No network IOCs: there are no URLs/IPs/domains; all targeting is via local device files (/dev/binder, /dev/hwbinder) and Android HIDL service interface strings. Overall, this is a PoC/bug trigger rather than a complete privilege escalation: it focuses on reliably reaching the vulnerable condition and exercising Binder driver behavior, without a post-trigger payload like ROP, shell, or persistence.
This repository is a sophisticated exploit development environment and proof-of-concept for attacking the Android Binder IPC subsystem. It includes a C library (libdevbinder) that abstracts Binder interactions, as well as example client and server programs, and several exploit/test harnesses (notably src/main.c and libdevbinder/src/exp.c). The code is designed to manipulate Binder transactions at a low level, including publishing and grabbing handles, sending crafted binder objects, and orchestrating multi-threaded or multi-process interactions to trigger race conditions or use-after-free vulnerabilities in the Binder kernel driver. The exploit is operational and can be adapted to target specific Binder vulnerabilities, but does not appear to be weaponized for a specific CVE. The main attack vector is local, requiring code execution on the target device with access to the Binder device node. The code is well-structured, modular, and includes both library and standalone exploit/test code.
This repository is a proof-of-concept (POC) exploit for CVE-2023-20938, a use-after-free vulnerability in the Android binder driver. The codebase is written in C and is structured into several modules: low-level binder/hwbinder interface wrappers (binder.c/h, hwbinder.c/h), utility functions (utils.c/h, base.h), and the main exploit logic (poc.c). The Makefile is provided for building the exploit binary. The exploit orchestrates binder transactions between two processes using the ITokenManager interface to create a scenario where a freed binder node is accessed, triggering a kernel use-after-free and resulting in a crash (as shown by KASAN logs in the README). The exploit is intended for research and demonstration purposes and does not provide a stable privilege escalation or shell. It targets Android 12 with kernel version 5.10.136_r00 on x86_64, and requires access to /dev/binder and /dev/hwbinder. The endpoints /dev/binder and /dev/hwbinder are fingerprintable as the exploit interacts directly with these device nodes.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.