Skip to finding
important · Mobile — Android Kernel

Android classifies a TIPC fragment-reassembly double-free as no-interaction remote kernel code execution, but stock-handset reachability remains unknown.

Affects

Android kernels containing the vulnerable Linux TIPC fragment-reassembly implementation.

Attacker-controlled fragments delivered to an enabled TIPC transport can leave a stale skb pointer that is freed twice after validation fails.

Detail and 3 sources

Google classifies the result as no-interaction kernel code execution, but no cited source establishes a reachable TIPC bearer on a factory-stock handset.

Chain to watch
Deliver attacker-controlled fragments to an enabled Android TIPC transport→↓Trigger the fragment-reassembly double-free→↓Reach kernel code execution→↓A stock-handset transport and attacker-reachable bearer have not been established.
Unverified chainAudit shipping OEM kernel configurations and bearer setup, then reproduce delivery on a bootloader-locked handset.

This remains Secondary because the published fix was not read for this brief.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Wednesday, September 9, 2026