CVE-2026-23407: apparmor: fix missing bounds check on DEFAULT table in verify_dfa()
apparmor: fix missing bounds check on DEFAULT table in verifydfa()
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Fixed in 6.19.0-rc7-next-20260127
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23407?
CVE-2026-23407 is classified as a medium severity vulnerability affecting the AppArmor functionality in the Linux kernel.
How do I fix CVE-2026-23407?
To fix CVE-2026-23407, upgrade to the latest version of the Linux kernel where the vulnerability has been patched.
What systems are affected by CVE-2026-23407?
CVE-2026-23407 affects systems running the AppArmor feature of the Linux kernel.
What is the impact of CVE-2026-23407?
The impact of CVE-2026-23407 could allow an attacker to exploit the missing bounds check, potentially leading to unauthorized actions within the system.
Is CVE-2026-23407 publicly known?
Yes, CVE-2026-23407 is a publicly known vulnerability that has been documented and assigned a CVE identifier.