[PATCH 0/2] binder: fix TF_UPDATE_TXN supersede cleanup bugs

Tomer Pomeranc <[email protected]>
Newsgroups org.kernel.vger.stable,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
Two bugs in the t_outdated cleanup path of binder_proc_transaction(),
both introduced by commit 9864bb480133 ("binder: add TF_UPDATE_TXN to
replace outdated txn"):

1. kfree(t_outdated) is called without binder_free_txn_fixups(),
   permanently leaking binder_txn_fd_fixup entries and their fget()'d
   struct file references. The refcount never reaches zero; the leak
   survives process exit and accumulates until file-max exhaustion.

2. binder_release_entire_buffer() is called with is_failure=false for
   a transaction that was never delivered. Since binder_apply_fd_fixups()
   was never called, the BINDER_TYPE_FDA handler reads stale buffer data
   as fd numbers and closes unrelated fds via binder_deferred_fd_close().

Confirmed on mainline Linux (6.8.0-124-generic, binder_linux module)
and Android (Pixel 8, kernel 6.1.124, /dev/hwbinder).

Tomer Pomeranc (2):
  binder: fix leaked fd fixups on TF_UPDATE_TXN supersede
  binder: fix is_failure flag for superseded transaction cleanup

 drivers/android/binder.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

-- 
2.34.1
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.