CVE-2026-64468 is a use-after-free race in the Linux kernel Binder IPC subsystem's binder_free_transaction() function. The function reads a transaction's target process pointer while holding the transaction lock, then drops that lock before acquiring the target process inner lock. In the intervening interval, concurrent teardown can free the target Binder process, causing binder_free_transaction() to lock and access freed memory. The fix pins the transaction target thread, ensuring that the associated target process remains alive until transaction cleanup is complete. Transactions with no target thread are not affected by this race because their target process can only be the current context on the relevant paths.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This is a standalone CVE-2026-64468 research and exploitation repository, not a framework module. Its main artifact, exploit.c, is a roughly 69 KB x86_64 C local privilege escalation against a process-lifetime use-after-free in Binder's binder_free_transaction(). It races teardown of a target binder_proc after its pointer is copied outside the transaction lock. On a successful race, System V message allocations reclaim the freed kmalloc-1k object with attacker-controlled data; a forged frozen wait queue redirects kernel control flow through a JOP dispatcher to commit_creds() with a forged credential, producing root. The repository also contains binder_chain_64468.c, an unprivileged Binder transaction-chain proof of concept for reliably reaching the race and obtaining KASAN slab-use-after-free reports on vulnerable kernels. The lab/ directory builds matched vulnerable and fixed upstream Linux worktrees, boots disposable QEMU initramfs guests, makes Binder accessible, and verifies the differential: the vulnerable parent commit 114a116aaa5f can produce KASAN UAF reports while fixed commit f223d27a546c does not. The demo/ directory is a separate end-to-end LPE laboratory. It builds an intentionally vulnerable but otherwise hardened/KASLR-enabled x86_64 kernel, creates a Debian 13 initramfs via Docker, exposes /dev/binder as mode 0666, compiles exploit.c inside the guest as uid 1000, and runs interactive or unattended root demonstrations. mkoffsets.sh is a Python utility that extracts target-specific symbols and JOP gadget offsets from vmlinux. Shell and Python scripts build kernels/rootfs images, run QEMU/KVM campaigns, collect JSON results, and record/render terminal demonstrations. No remote network target, callback, C2, or network service interaction is present; the attack surface is the locally exposed Binder device.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.