CVE-2026-23406: apparmor: fix side-effect bug in match_char() macro usage
Published Apr 1, 2026
·Updated
apparmor: fix side-effect bug in matchchar() macro usage
Affected Software
17 affected componentsFixes available
Linux AppArmor (Linux kernel)
Microsoft azl3 kernel 6.6.0.0-1
Linux Linux kernel>=4.17.1<5.10.253
Linux Linux kernel>=5.11<5.15.203
Linux Linux kernel>=5.16<6.1.169
Linux Linux kernel>=6.2<6.6.130
Linux Linux kernel>=6.7<6.12.77
Linux Linux kernel>=6.13<6.18.18
Linux Linux kernel>=6.19<6.19.8
Linux Linux kernel=4.17
Linux Linux kernel=7.0-rc1
Linux Linux kernel=7.0-rc2
Linux Linux kernel=7.0-rc3
Linux Linux kernel=7.0-rc4
Linux Linux kernel=7.0-rc5
Linux Linux kernel=7.0-rc6
Linux Linux kernel=7.0-rc7
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.19.0-rc7-next-20260127 #1 PREEMPT(lazy)Patch apparmor: fix side-effect bug in match_char() macro usage
Event History
Apr 1, 2026
CVE Published
via MITRE·08:36 AM
Data Sourced
via MITRE·08:36 AM
DescriptionSeverity
Data Sourced
via NVD·09:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 10, 2026
Data Sourced
via Microsoft·08:02 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:02 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-23406?
CVE-2026-23406 is classified as a medium severity vulnerability due to a bug in the match_char() macro usage in the AppArmor module of the Linux kernel.
2
How do I fix CVE-2026-23406?
To fix CVE-2026-23406, update the Linux kernel to the latest version where this vulnerability has been patched.
3
What is affected by CVE-2026-23406?
CVE-2026-23406 affects the AppArmor module in the Linux kernel.
4
What kind of vulnerability is CVE-2026-23406?
CVE-2026-23406 is a side-effect bug related to macro usage in the AppArmor security module.
5
Is there a workaround for CVE-2026-23406?
There is no official workaround for CVE-2026-23406; updating the kernel is the recommended approach.