Junglewise Threat Intelligence

CVE-2026-43434: Linux Kernel Rust Binder improper VMA ownership check

CVE-2026-43434 · Severity: high · CVSS 7.8 · Published 2026-05-08

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Rust implementation of the Binder driver could allow a local attacker to gain unauthorized write access to memory pages that are intended to be read-only. Binder is a critical component used for communication between different processes, particularly in Android environments. If exploited, this could allow an attacker to bypass security boundaries and potentially compromise the integrity of the system or user data.

Technical details

A race condition or logic error exists in the Rust Binder implementation where it performs VMA lookups by address without verifying ownership or identity. When installing or zapping pages, if a VMA is closed and replaced by a different VMA at the same address, Rust Binder may interact with the incorrect VMA. This can lead to the driver installing pages into a writable VMA, granting write access to pages that should be read-only. The fix involves storing a pointer in vm_private_data and verifying both vm_ops and vm_private_data during vma_lookup() to ensure the VMA belongs to the Binder process.

Affected products

  • Linux Linux Kernel 6.18 to 6.18.19, 6.19 to 6.19.9, 7.0-rc1 to 7.0-rc3

Timeline

  • 2026-02-18: other: Vulnerability reported by Google Project Zero
  • 2026-05-08: advisory
  • 2026-05-08: disclosed

References

Related threats