SB20260918445 - Improper access control in Linux kernel apparmor
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper access control (CVE-ID: CVE-2026-90231)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escape AppArmor confinement.
The vulnerability exists due to improper access control in AppArmor profile transition handling when executing two transitions through an unconfined profile. A local user can execute two transitions through an unconfined profile to escape AppArmor confinement.
The issue applies when unprivileged transitions to unconfined profiles are restricted.
Remediation
Install update from vendor's website.