[PATCH 0/2] binder: fix TF_UPDATE_TXN supersede cleanup bugs
From: Tomer Pomeranc
Date: Wed Aug 12 2026 - 15:55:17 EST
Two bugs in the t_outdated cleanup path of binder_proc_transaction(),
both introduced by commit 9864bb480133 ("binder: add TF_UPDATE_TXN to
replace outdated txn"):
1. kfree(t_outdated) is called without binder_free_txn_fixups(),
permanently leaking binder_txn_fd_fixup entries and their fget()'d
struct file references. The refcount never reaches zero; the leak
survives process exit and accumulates until file-max exhaustion.
2. binder_release_entire_buffer() is called with is_failure=false for
a transaction that was never delivered. Since binder_apply_fd_fixups()
was never called, the BINDER_TYPE_FDA handler reads stale buffer data
as fd numbers and closes unrelated fds via binder_deferred_fd_close().
Confirmed on mainline Linux (6.8.0-124-generic, binder_linux module)
and Android (Pixel 8, kernel 6.1.124, /dev/hwbinder).
Tomer Pomeranc (2):
binder: fix leaked fd fixups on TF_UPDATE_TXN supersede
binder: fix is_failure flag for superseded transaction cleanup
drivers/android/binder.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--
2.34.1