CVE-2022-50240
published 2025-09-15CVE-2022-50240: In the Linux kernel, the following vulnerability has been resolved: android: binder: stop saving a pointer to the VMA Do not record a pointer to a VMA outside…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.15%
5.0th percentile
In the Linux kernel, the following vulnerability has been resolved:
android: binder: stop saving a pointer to the VMA
Do not record a pointer to a VMA outside of the mmap_lock for later use.
This is unsafe and there are a number of failure paths *after* the
recorded VMA pointer may be freed during setup. There is no callback to
the driver to clear the saved pointer from generic mm code. Furthermore,
the VMA pointer may become stale if any number of VMA operations end up
freeing the VMA so saving it was fragile to being with.
Instead, change the binder_alloc struct to record the start address of the
VMA and use vma_lookup() to get the vma when needed. Add lockdep
mmap_lock checks on updates to the vma pointer to ensure the lock is held
and depend on that lock for synchronization of readers and writers - which
was already the case anyways, so the smp_wmb()/smp_rmb() was not
necessary.
[[email protected]: fix drivers/android/binder_alloc_selftest.c]
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.19.6-1 (bookworm) | linux 5.19.6-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= dd2283f2605e3b3e9c61bcae844b34f2afa4813f < 27a594bc7a7c8238d239e3cdbcf2edfa3bbe9a1b | 27a594bc7a7c8238d239e3cdbcf2edfa3bbe9a1b |
| linux | linux | >= dd2283f2605e3b3e9c61bcae844b34f2afa4813f < 015ac18be7de25d17d6e5f1643cb3b60bfbe859e | 015ac18be7de25d17d6e5f1643cb3b60bfbe859e |
| linux | linux | >= dd2283f2605e3b3e9c61bcae844b34f2afa4813f < 622ef885a89ad04cfb76ee478fb44f051125d1f1 | 622ef885a89ad04cfb76ee478fb44f051125d1f1 |
| linux | linux | >= dd2283f2605e3b3e9c61bcae844b34f2afa4813f < 925e6b6f82c9c80ab3c17acbde8d16f349da7d26 | 925e6b6f82c9c80ab3c17acbde8d16f349da7d26 |
| linux | linux | >= dd2283f2605e3b3e9c61bcae844b34f2afa4813f < 1ec3f76a436d750fd5023caec5da0494fc2870d2 | 1ec3f76a436d750fd5023caec5da0494fc2870d2 |
| linux | linux | >= dd2283f2605e3b3e9c61bcae844b34f2afa4813f < a43cfc87caaf46710c8027a8c23b8a55f1078f19 | a43cfc87caaf46710c8027a8c23b8a55f1078f19 |
| linux | linux_kernel | >= 0 < 5.10.158-1 | 5.10.158-1 |
| linux | linux_kernel | >= 0 < 5.19.6-1 | 5.19.6-1 |
| linux | linux_kernel | >= 0 < 5.19.6-1 | 5.19.6-1 |
| linux | linux_kernel | >= 0 < 5.19.6-1 | 5.19.6-1 |
| linux | linux_kernel | >= 4.20 < 5.4.224 | 5.4.224 |
| linux | linux_kernel | >= 5.11 < 5.15.61 | 5.15.61 |
| linux | linux_kernel | >= 5.16 < 5.18.18 | 5.18.18 |
| linux | linux_kernel | >= 5.19 < 5.19.2 | 5.19.2 |
| linux | linux_kernel | >= 5.5 < 5.10.154 | 5.10.154 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2022-50240: In the Linux kernel, the following vulnerability has been resolved: android: binder: stop saving a pointer to the VMA Do not record a pointer to a VMA
osv·2025-09-15·CVSS 7.8
CVE-2022-50240 [HIGH] CVE-2022-50240: In the Linux kernel, the following vulnerability has been resolved: android: binder: stop saving a pointer to the VMA Do not record a pointer to a VMA
In the Linux kernel, the following vulnerability has been resolved: android: binder: stop saving a pointer to the VMA Do not record a pointer to a VMA outside of the mmap_lock for later use. This is unsafe and there are a number of failure paths *after* the recorded VMA pointer may be freed during setup. There is no callback to the driver to clear the saved pointer from generic mm code. Furthermore, the VMA pointer may become stale if any number of VMA operations end up freeing the VMA so saving it was fragile to being with. Instead, change the binder_alloc struct to record the start address of the VMA and use vma_lookup() to get the vma when needed. Add lockdep mmap_lock checks on updates to the vma pointer to ensure the lock is held and depend on that lock for synchronization of readers
GHSA
GHSA-4cpm-89f2-8grm: In the Linux kernel, the following vulnerability has been resolved:
binder: fix UAF of alloc->vma in race with munmap()
In commit 720c24192404 ("AND
ghsa_unreviewed·2025-09-15
CVE-2022-50240 [HIGH] CWE-416 GHSA-4cpm-89f2-8grm: In the Linux kernel, the following vulnerability has been resolved:
binder: fix UAF of alloc->vma in race with munmap()
In commit 720c24192404 ("AND
In the Linux kernel, the following vulnerability has been resolved:
binder: fix UAF of alloc->vma in race with munmap()
In commit 720c24192404 ("ANDROID: binder: change down_write to
down_read") binder assumed the mmap read lock is sufficient to protect
alloc->vma inside binder_update_page_range(). This used to be accurate
until commit dd2283f2605e ("mm: mmap: zap pages with read mmap_sem in
munmap"), which now downgrades the mmap_lock after detaching the vma
from the rbtree in munmap(). Then it proceeds to teardown and free the
vma with only the read lock held.
This means that accesses to alloc->vma in binder_update_page_range() now
will race with vm_area_free() in munmap() and can cause a UAF as shown
in the following KASAN trace:
BUG: KASAN: use-after-free in vm_insert_page+0x7c/0x1
Red Hat
kernel: binder: fix UAF of alloc->vma in race with munmap()
vendor_redhat·2025-09-15·CVSS 7.8
CVE-2022-50240 [HIGH] kernel: binder: fix UAF of alloc->vma in race with munmap()
kernel: binder: fix UAF of alloc->vma in race with munmap()
In the Linux kernel, the following vulnerability has been resolved:
android: binder: stop saving a pointer to the VMA
Do not record a pointer to a VMA outside of the mmap_lock for later use.
This is unsafe and there are a number of failure paths *after* the
recorded VMA pointer may be freed during setup. There is no callback to
the driver to clear the saved pointer from generic mm code. Furthermore,
the VMA pointer may become stale if any number of VMA operations end up
freeing the VMA so saving it was fragile to being with.
Instead, change the binder_alloc struct to record the start address of the
VMA and use vma_lookup() to get the vma when needed. Add lockdep
mmap_lock checks on updates to the vma pointer to ensure the lock is
Debian
CVE-2022-50240: linux - In the Linux kernel, the following vulnerability has been resolved: android: bi...
vendor_debian·2022·CVSS 7.8
CVE-2022-50240 [HIGH] CVE-2022-50240: linux - In the Linux kernel, the following vulnerability has been resolved: android: bi...
In the Linux kernel, the following vulnerability has been resolved: android: binder: stop saving a pointer to the VMA Do not record a pointer to a VMA outside of the mmap_lock for later use. This is unsafe and there are a number of failure paths *after* the recorded VMA pointer may be freed during setup. There is no callback to the driver to clear the saved pointer from generic mm code. Furthermore, the VMA pointer may become stale if any number of VMA operations end up freeing the VMA so saving it was fragile to being with. Instead, change the binder_alloc struct to record the start address of the VMA and use vma_lookup() to get the vma when needed. Add lockdep mmap_lock checks on updates to the vma pointer to ensure the lock is held and depend on that lock for synchronization of readers
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/015ac18be7de25d17d6e5f1643cb3b60bfbe859ehttps://git.kernel.org/stable/c/1ec3f76a436d750fd5023caec5da0494fc2870d2https://git.kernel.org/stable/c/27a594bc7a7c8238d239e3cdbcf2edfa3bbe9a1bhttps://git.kernel.org/stable/c/622ef885a89ad04cfb76ee478fb44f051125d1f1https://git.kernel.org/stable/c/925e6b6f82c9c80ab3c17acbde8d16f349da7d26https://git.kernel.org/stable/c/a43cfc87caaf46710c8027a8c23b8a55f1078f19
2025-09-15
Published