๐Ÿ” CVE Alert

CVE-2026-64467

UNKNOWN 0.0

rust_binder: use a u64 stride when cleaning up the offsets array

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: rust_binder: use a u64 stride when cleaning up the offsets array Allocation's Drop walks the offsets array (binder_size_t = u64 entries), cleaning up the objects, but it used usize instead of u64 for both the stride and the per-entry read. On 64-bit kernels (usize == u64) this is harmless, but on 32-bit kernels it walks the 8-byte entries in 4-byte steps, iterating an N-entry array 2N times, and reads the always-zero high word as offset 0, cleaning up the object at offset 0 N extra times. As a result the referenced node or handle ends up with a lower reference count than it actually has (a refcount over-decrement), and binder's reference accounting is corrupted; for example, the owner can be notified of a strong reference release (BR_RELEASE) even though references still remain. Change the stride to u64, and read each entry as a u64, narrowing it to usize with try_into(). On 32-bit ARM, when this over-decrement would drive a count below zero, the driver's existing refcount guard refuses it and fires: rust_binder: Failure: refcount underflow!

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
eafedbc7c050c44744fbdf80bdf3315e860b7513 < 89b8cc948dce661af87527623b3a41cdd115e2f9 eafedbc7c050c44744fbdf80bdf3315e860b7513 < 74920b1b4e474ba7a4de4323c0458deec49d210b eafedbc7c050c44744fbdf80bdf3315e860b7513 < 803c8a9502e9b97cd6ae937618ef4a8fd6274343
Linux / Linux
6.18

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/89b8cc948dce661af87527623b3a41cdd115e2f9 git.kernel.org: https://git.kernel.org/stable/c/74920b1b4e474ba7a4de4323c0458deec49d210b git.kernel.org: https://git.kernel.org/stable/c/803c8a9502e9b97cd6ae937618ef4a8fd6274343