CVE-2026-23405: apparmor: fix: limit the number of levels of policy namespaces
Published Apr 1, 2026
·Updated
apparmor: fix: limit the number of levels of policy namespaces
Other sources
In the Linux kernel, the following vulnerability has been resolved:
— Launchpad
Affected Software
18 affected componentsFixes available
Linux Linux kernel (AppArmor)
Microsoft azl3 kernel 6.6.0.0-1
Linux Linux kernel>=2.6.36.1<5.10.253
Linux Linux kernel>=5.11<5.15.203
Linux Linux kernel>=5.16<6.1.169
Linux Linux kernel>=6.2<6.6.130
Linux Linux kernel>=6.7<6.12.77
Linux Linux kernel>=6.13<6.18.18
Linux Linux kernel>=6.19<6.19.8
Linux Linux kernel=2.6.36
Linux Linux kernel=7.0-rc1
Linux Linux kernel=7.0-rc2
Linux Linux kernel=7.0-rc3
Linux Linux kernel=7.0-rc4
Linux Linux kernel=7.0-rc5
Linux Linux kernel=7.0-rc6
Linux Linux kernel=7.0-rc7
debian/linux<=5.10.223-1
5.10.251-56.1.170-36.1.172-16.12.86-16.12.88-17.0.7-1
Remediation
Event History
Apr 1, 2026
CVE Published
via MITRE·08:36 AM
Data Sourced
via MITRE·08:36 AM
Description
Data Sourced
via NVD·09:16 AM
RemedyDescriptionSeverityAffected Software
Apr 10, 2026
Data Sourced
via Microsoft·08:02 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:02 AM
DescriptionSeverity
May 13, 2026
Data Sourced
via Launchpad·04:06 AM
Description
May 14, 2026
Data Sourced
via Ubuntu·04:06 AM
RemedyDescriptionSeverityAffected Software
May 17, 2026
Data Sourced
via Debian·04:10 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-23405?
CVE-2026-23405 has been classified with a moderate severity level due to its potential impact on policy namespace limitations.
2
What systems are affected by CVE-2026-23405?
CVE-2026-23405 affects the Linux kernel specifically in relation to the AppArmor security module.
3
How do I fix CVE-2026-23405?
To address CVE-2026-23405, ensure that your Linux kernel is updated to the latest version that patches this vulnerability.
4
What is the nature of CVE-2026-23405?
CVE-2026-23405 is a vulnerability related to the lack of limits on the number of policy namespaces in the AppArmor component of the Linux kernel.
5
When was CVE-2026-23405 addressed?
CVE-2026-23405 was resolved in recent updates to the Linux kernel, specifically related to AppArmor.