VYPR
High severity7.8NVD Advisory· Published Apr 1, 2026· Updated Apr 24, 2026

CVE-2026-23408

CVE-2026-23408

Description

In the Linux kernel, the following vulnerability has been resolved:

apparmor: Fix double free of ns_name in aa_replace_profiles()

if ns_name is NULL after 1071 error = aa_unpack(udata, &lh, &ns_name);

and if ent->ns_name contains an ns_name in 1089 } else if (ent->ns_name) {

then ns_name is assigned the ent->ns_name 1095 ns_name = ent->ns_name;

however ent->ns_name is freed at 1262 aa_load_ent_free(ent);

and then again when freeing ns_name at 1270 kfree(ns_name);

Fix this by NULLing out ent->ns_name after it is transferred to ns_name

")

Affected products

9
  • Linux/Kernel9 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 8 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=5.5.1,<5.10.253
    • cpe:2.3:o:linux:linux_kernel:5.5:-:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.0:rc1:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.0:rc2:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.0:rc3:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.0:rc4:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.0:rc5:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.0:rc6:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:7.0:rc7:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

News mentions

0

No linked articles in our index yet.