CVE-2026-47328: fallo de gravedad media en Canonical Ubuntu Linux
Invalid pointer deallocation in Ubuntu Linux AppArmor notification handling
Publicada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 6.1epss 0.1%
probabilidad de explotación
0.1%top 98% de las CVE
explotación observada
noninguna fuente lo reporta
Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to resource exhaustion.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Productos afectados
Canonical · Ubuntu LinuxCVEs relacionadas — Canonical Ubuntu Linux
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-47331HIGHUse-after-free in Ubuntu Linux AppArmor notification handlingEPSS 0.2%CVE-2026-47333HIGHOut-of-bounds read in Ubuntu Linux AppArmor notification handlingEPSS 0.2%CVE-2025-13350HIGHUse-after-free of orphaned AF_UNIX in Ubuntu builds of Linux kernelEPSS 0.2%CVE-2026-47332MEDIUMOut-of-bounds read in Ubuntu Linux AppArmor notification handlingEPSS 0.1%CVE-2026-47335MEDIUMNULL pointer dereference in Ubuntu Linux AppArmor notification handlingEPSS 0.1%CVE-2026-47326MEDIUMMemory leak in Ubuntu Linux AppArmor large notification response allocationEPSS 0.1%