Home

Description

Ubuntu Linux 6.8 GA retains the legacy AF_UNIX garbage collector but backports upstream commit 8594d9b85c07 ("af_unix: Don’t call skb_get() for OOB skb"). When orphaned MSG_OOB sockets hit unix_gc(), the garbage collector still calls kfree_skb() as if OOB SKBs held two references; on Ubuntu Linux 6.8 (Noble Numbat) kernel tree, they have only the queue reference, so the buffer is freed while still reachable and subsequent queue walks dereference freed memory, yielding a reliable local privilege escalation (LPE) caused by a use-after-free (UAF). Ubuntu builds that have already taken the new GC stack from commit 4090fa373f0e, and mainline Linux kernels shipping that infrastructure are unaffected because they no longer execute the legacy collector path. This issue affects Ubuntu Linux from 6.8.0-56.58 before 6.8.0-84.84.

PUBLISHED Reserved 2025-11-18 | Published 2026-03-05 | Updated 2026-03-06 | Assigner canonical




HIGH: 7.1CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:L/SC:H/SI:H/SA:H

Problem types

CWE-416 Use After Free

Product status

Default status
unaffected

6.8.0-56.58 (dpkg) before 6.8.0-84.84
affected

Credits

Noam Rathaus finder

References

www.openwall.com/lists/oss-security/2026/03/05/7

bugs.launchpad.net/ubuntu/+source/linux/+bug/2121515 issue-tracking

git.launchpad.net/...9cbc2a1d4f61e492ddac5da65b075836675f94d patch

cve.org (CVE-2025-13350)

nvd.nist.gov (CVE-2025-13350)

Download JSON