SB20260918445 - Improper access control in Linux kernel apparmor



SB20260918445 - Improper access control in Linux kernel apparmor

Published: September 18, 2026

Security Bulletin ID SB20260918445
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper access control (CVE-ID: CVE-2026-90231)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escape AppArmor confinement.

The vulnerability exists due to improper access control in AppArmor profile transition handling when executing two transitions through an unconfined profile. A local user can execute two transitions through an unconfined profile to escape AppArmor confinement.

The issue applies when unprivileged transitions to unconfined profiles are restricted.


Remediation

Install update from vendor's website.