CVE-2025-13350Disclosure

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Ubuntu Linux 6.8 GA retains the legacy AF_UNIX garbage collector but backports upstream commit 8594d9b85c07 ("af_unix: Don’t call skb_get() for OOB skb"). When orphaned MSG_OOB sockets hit unix_gc(), the garbage collector still calls kfree_skb() as if OOB SKBs held two references; on Ubuntu Linux 6.8 (Noble Numbat) kernel tree, they have only the queue reference, so the buffer is freed while still reachable and subsequent queue walks dereference freed memory, yielding a reliable local privilege escalation (LPE) caused by a use-after-free (UAF). Ubuntu builds that have already taken the new GC stack from commit 4090fa373f0e, and mainline Linux kernels shipping that infrastructure are unaffected because they no longer execute the legacy collector path. This issue affects Ubuntu Linux from 6.8.0-56.58 before 6.8.0-84.84.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-05); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-05: 2Mentions · 2026-03-06: 1Mentions · 2026-03-09: 1Patch / Workaround · 2026-03-09: 1Technical Details · 2026-03-05: 2Technical Details · 2026-03-06: 1Technical Details · 2026-03-09: 103-0503-0603-09
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-052
Disclosure2
2026-03-061
Disclosure1
2026-03-091
Patch1
Full discourse4 posts
  • Brad Spengler@spendergrsec
    Disclosure

    https://seclists.org/oss-sec/2026/q1/261 (CVE-2025-13350) is for: https://ssd-disclosure.com/lpe-via-refcount-imbalance-in-the-af_unix-of-ubuntus-kernel/ from last year

    Post summary

    The post links to a disclosure page for CVE‑2025‑13350, a local privilege escalation vulnerability in Ubuntu’s AF_UNIX kernel, but does not provide a PoC, exploit code, active exploitation claim, or patch details.

    10030182.1K
    4.4K followersView on X
  • Open Source Security mailing list@oss_security
    Patch

    CVE-2025-13350 for Ubuntu Linux kernel https://www.openwall.com/lists/oss-security/2026/03/05/7 Incorrectly backported patch that caused [Ubuntu] to mix an old-style with a new-style garbage collector for Unix Domain Sockets. If you consume the upstream kernel directly, you're fine.

    Post summary

    CVE-2025-13350 arises from an incorrectly backported patch in Ubuntu’s kernel that mixes two garbage collector styles for Unix Domain Sockets; the recommended mitigation is to use the upstream kernel.

    00063638
    4.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-13350 Local Privilege Escalation in Ubuntu Linux 6.8 via AF_UNIX Garbage Collector UAF https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-13350

    Post summary

    The post announces CVE-2025-13350, a local privilege escalation flaw in Ubuntu 6.8's AF_UNIX garbage collector, without providing any PoC, exploit code, patch, or evidence of active exploitation.

    0000084
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-13350 Ubuntu Linux 6.8 GA retains the legacy AF_UNIX garbage collector but backports upstream commit 8594d9b85c07 ("af_unix: Don’t call skb_get() for OOB skb"). When orphan… https://www.cve.org/CVERecord?id=CVE-2025-13350

    Post summary

    The post references CVE-2025-13350, noting a commit affecting AF_UNIX processing in Ubuntu Linux 6.8, but provides no evidence of exploitation, patches, or a PoC.

    00000121
    56.6K followersView on X

Explore more