← back
CVE-2026-47328

Invalid pointer deallocation in Ubuntu Linux AppArmor notification handling

CVSS 6.1 MEDIUMEPSS 0.1%CWE-590
Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to resource exhaustion.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Affected products
Canonical · Ubuntu Linux

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →