Hide Forgot
A race condition in the Linux kernel may lead to malicious code being able to free buffers using the BC_FREE_BUFFER ioctl to binder and trigger use-after-free in android/binder.c causing denial of service. Upstream patch: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=7bada55ab50697861eee6bb7d60b41e68a961a9c
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 1696021]
While Fedora does not enable the android drivers, this was fixed upstream in 4.20 kernels.