SB2026040158 - Double free in Linux kernel apparmor
Published: April 1, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Double free (CVE-ID: CVE-2026-23408)
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a double free in the AppArmor profile replacement component when processing user-supplied profile data. A local user can send a specially crafted request to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/18b5233e860c294a847ee07869d93c0b8673a54b
- https://git.kernel.org/stable/c/55ef2af7490aaf72f8ffe11ec44c6bcb7eb2162a
- https://git.kernel.org/stable/c/5df0c44e8f5f619d3beb871207aded7c78414502
- https://git.kernel.org/stable/c/7998ab3010d2317643f91828f1853d954ef31387
- https://git.kernel.org/stable/c/86feeccd6b93ed94bd6655f30de80f163f8d5a45