{"id":"ASB-A-320661088","details":"In binder_alloc_copy_to_buffer of binder.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.","aliases":["A-320661088","CVE-2024-26926"],"modified":"2026-03-11T06:31:38.396580Z","published":"2024-06-01T00:00:00Z","references":[{"type":"ADVISORY","url":"https://source.android.com/security/bulletin/2024-06-01"},{"type":"FIX","url":"https://android.googlesource.com/kernel/common/+/bf4f9bc41c3b5203e1e7284e1de78e82f0630473"},{"type":"FIX","url":"https://android.googlesource.com/kernel/common/+/7a2aa337ab8235460c1efa92a846eaeade5f2514"}],"affected":[{"package":{"name":":linux_kernel:","ecosystem":"Android"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":":0"},{"fixed":":2024-06-05"}]}],"versions":["Kernel"],"ecosystem_specific":{"fixes":["https://android.googlesource.com/kernel/common/+/bf4f9bc41c3b5203e1e7284e1de78e82f0630473","https://android.googlesource.com/kernel/common/+/7a2aa337ab8235460c1efa92a846eaeade5f2514"],"vanir_signatures":[{"id":"ASB-A-320661088-1c1d774f","deprecated":false,"signature_version":"v1","source":"https://android.googlesource.com/kernel/common/+/7a2aa337ab8235460c1efa92a846eaeade5f2514","digest":{"function_hash":"66753507924836775910400560798142281790","length":957},"signature_type":"Function","target":{"function":"binder_get_object","file":"drivers/android/binder.c"}},{"id":"ASB-A-320661088-79c2ae95","deprecated":false,"signature_version":"v1","source":"https://android.googlesource.com/kernel/common/+/bf4f9bc41c3b5203e1e7284e1de78e82f0630473","digest":{"function_hash":"66753507924836775910400560798142281790","length":957},"signature_type":"Function","target":{"function":"binder_get_object","file":"drivers/android/binder.c"}},{"id":"ASB-A-320661088-b04bf23b","deprecated":false,"signature_version":"v1","source":"https://android.googlesource.com/kernel/common/+/7a2aa337ab8235460c1efa92a846eaeade5f2514","digest":{"threshold":0.9,"line_hashes":["29115821783006995889220911580082480479","280393994292968683621617742395637642131","324603365971076042156409818351823863238","313249326651371733232230128638963259074","35997565425222343542021450846225411228"]},"signature_type":"Line","target":{"file":"drivers/android/binder.c"}},{"id":"ASB-A-320661088-d47c8524","deprecated":false,"signature_version":"v1","source":"https://android.googlesource.com/kernel/common/+/bf4f9bc41c3b5203e1e7284e1de78e82f0630473","digest":{"threshold":0.9,"line_hashes":["29115821783006995889220911580082480479","280393994292968683621617742395637642131","324603365971076042156409818351823863238","313249326651371733232230128638963259074","35997565425222343542021450846225411228"]},"signature_type":"Line","target":{"file":"drivers/android/binder.c"}}],"types":["EoP"],"severity":"High","spl":"2024-06-05"},"database_specific":{"source":"https://storage.googleapis.com/android-osv-test/ASB-A-320661088.json"}}],"schema_version":"1.7.5"}