CVE-2024-56556·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: binder: fix node UAF in binder_add_freeze_work() In binder_add_freeze_work() we iterate over the proc->nodes with the proc->inner_lock held. However, this lock is temporarily dropped in order to acquire the node->lock first (lock nesting order). This can race with binder_node_release() and trigger a use-after-free: ================================================================== BUG: KASAN: slab-use-after-free in _raw_spin_lock+0xe4/0x19c Write of size 4 at addr ffff53c04c29dd04 by task freeze/640 CPU: 5 UID: 0 PID: 640 Comm: freeze Not tainted 6.11.0-07343-ga727812a8d45 #17 Hardware name: linux,dummy-virt (DT) Call trace: _raw_spin_lock+0xe4/0x19c binder_add_freeze_work+0x148/0x478 binder_ioctl+0x1e70/0x25ac __arm64_sys_ioctl+0x124/0x190 Allocated by task 637: __kmalloc_cache_noprof+0x12c/0x27c binder_new_node+0x50/0x700 binder_transaction+0x35ac/0x6f74 binder_thread_write+0xfb8/0x42a0 binder_ioctl+0x18f0/0x25ac __arm64_sys_ioctl+0x124/0x190 Freed by task 637: kfree+0xf0/0x330 binder_thread_read+0x1e88/0x3a68 binder_ioctl+0x16d8/0x25ac __arm64_sys_ioctl+0x124/0x190 ================================================================== Fix the race by taking a temporary reference on the node before releasing the proc->inner lock. This ensures the node remains alive while in use.
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.12.4
- Published
- 2024-12-27
Affected versions
From: 6.12
Until: 6.12.4
Fixed in: 6.12.4
How to fix this CVE
Update the Linux kernel to version 6.12.4 or later to patch a use-after-free vulnerability in the binder subsystem that could lead to kernel memory corruption. This fix adds reference counting to prevent nodes from being freed while still in use during freeze operations. Reboot your system after applying the kernel update to activate the patched version.
sudo dnf update kernelDefensia detects this vulnerability
How to check if you are affected
- Step 1: Check your current kernel version by running `uname -r` and verify it is earlier than 6.12.4
- Step 2: Confirm the binder subsystem is enabled in your kernel configuration by checking `grep CONFIG_ANDROID_BINDER /boot/config-$(uname -r)` for 'y' value
- Step 3: Search kernel logs for UAF-related crashes using `dmesg | grep -i 'use-after-free\|kasan\|binder_add_freeze'`
- Step 4: After patching, verify the new kernel is running with `uname -r` and confirm it shows 6.12.4 or later
FAQ
What is CVE-2024-56556?
This vulnerability is a use-after-free flaw in the Linux kernel's binder IPC subsystem that occurs when the proc->inner_lock is temporarily released during node freeze operations, allowing concurrent access to already-freed memory structures. An attacker with local access and sufficient privileges can trigger a kernel crash or memory corruption.
Is CVE-2024-56556 being actively exploited?
No, this vulnerability is not currently listed on the CISA KEV catalog and no public exploits are known to be available.
What versions of Kernel are affected by CVE-2024-56556?
Linux kernel versions 6.12.0 through 6.12.3 are affected. Version 6.12.4 and later contain the fix.
How do I check if my server is vulnerable to CVE-2024-56556?
Run `uname -r` and check if the version is between 6.12.0 and 6.12.3. Additionally, verify binder is enabled with `grep CONFIG_ANDROID_BINDER /boot/config-$(uname -r)` showing 'y'.
Does Defensia detect CVE-2024-56556?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server running versions 6.12.0-6.12.3, CVE-2024-56556 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-56556. Free for 1 server.
Get started free