Google Project Zero disclosed a Linux kernel vulnerability affecting Linux >= 6.9 in which broken handling of AF_UNIX MSG_OOB traffic can trigger a use-after-free (UAF) condition, enabling both read and write access to freed memory. The issue was published in Project Zero's tracker as issue 423023990, indicating a memory-safety flaw in the kernel's UNIX domain socket implementation rather than an application-level bug.
The available references do not include a vendor advisory, patch details, CVE assignment, or exploitation evidence, but the bug title indicates potentially serious impact because kernel-level UAF read/write conditions can often be leveraged for privilege escalation or system compromise. Security teams running Linux kernels in the affected branch should monitor upstream kernel fixes and distribution backports, prioritize patch validation for systems that rely on local socket communication, and assess exposure in environments where untrusted local code execution is possible.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
A Project Zero issue was published describing a Samsung QuramDng getOverlap miscalculation that leads to integer overflow and subsequent out-of-bounds read and write. The issue was published on 2025-11-04.
A Project Zero issue was published describing a Linux kernel vulnerability affecting Linux 6.9 and later, where broken AF_UNIX MSG_OOB handling causes a use-after-free enabling read and write. Duplicate references point to the same issue publication.
A Project Zero issue was published describing a V8 Turbofan bug where JSCallReducer::ReduceArrayIndexOfIncludes fails to insert Map checks. The issue was published on 2019-03-20.
A Project Zero issue was published describing a V8 Turbofan flaw in which optimizing Reflect.construct may read a Map pointer out of bounds. The issue was published on 2019-03-07.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
project-zero.issues.chromium.org
Open sourceproject-zero.issues.chromium.org
Open sourceproject-zero.issues.chromium.org
Open sourcebugs.chromium.org
Open sourcebugs.chromium.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.