PT-2025-28356 · Linux+6 · Linux Kernel+6

Jann Horn

·

Published

2025-06-18

·

Updated

2026-05-07

·

CVE-2025-38236

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions 6.9 and earlier, including versions prior to 6.1.143, 6.6.96, 6.12.36, and 6.15.5.
Description:
The Linux kernel contains a use-after-free vulnerability in the af unix module, specifically within the unix stream read generic() function. This flaw can be triggered by sending crafted AF UNIX socket messages, potentially allowing a local attacker to achieve privilege escalation and bypass the Chrome sandbox. The vulnerability occurs when handling out-of-band (OOB) data, where consecutive consumed OOB skbs are not properly managed, leading to memory corruption. A proof-of-concept exploit is publicly available.
Recommendations:
Upgrade to Linux kernel version 6.1.143 or later. Upgrade to Linux kernel version 6.6.96 or later. Upgrade to Linux kernel version 6.12.36 or later. Upgrade to Linux kernel version 6.15.5 or later. Upgrade to Linux kernel version 6.6.101 or later.

Exploit

Fix

LPE

Use After Free

Weakness Enumeration

Related Identifiers

ASB-A-432753641
AZL-64799
AZL-72781
BDU:2025-09670
CVE-2025-38236
DLA-4328-1
DSA-5973-1
ECHO-7457-7483-AE4D
MGASA-2025-0218
MGASA-2025-0219
SUSE-SU-2025:02853-1
SUSE-SU-2025:02923-1
SUSE-SU-2025:02969-1
SUSE-SU-2025:02996-1
SUSE-SU-2025:02997-1
SUSE-SU-2025:03011-1
SUSE-SU-2025:03023-1
SUSE-SU-2025:20577-1
SUSE-SU-2025:20586-1
SUSE-SU-2025:20601-1
SUSE-SU-2025:20602-1
SUSE-SU-2025_02853-1
SUSE-SU-2025_02969-1
SUSE-SU-2025_02996-1
SUSE-SU-2025_02997-1
SUSE-SU-2025_03011-1
SUSE-SU-2025_03023-1
USN-7833-1
USN-7833-2
USN-7833-3
USN-7833-4
USN-7834-1
USN-7856-1
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8033-1
USN-8033-2
USN-8033-3
USN-8033-4
USN-8033-5
USN-8033-6
USN-8033-7
USN-8033-8
USN-8034-1
USN-8034-2
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1
USN-8141-1
USN-8163-1
USN-8163-2
USN-8243-1

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu