CVE-2026-47326: Memory leak in Ubuntu Linux AppArmor large notification response allocation
Last updated 5 June 2026
Other sources
Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory leak could lead to resource exhaustion.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.257-1Fixed in 6.1.170-3Fixed in 6.1.174-1Fixed in 6.12.86-1Fixed in 6.12.90-2Fixed in 7.0.10-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.257-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.170-3 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.174-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.12.86-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.12.90-2 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 7.0.10-1 - Compensating control
Restrict or remove untrusted/unprivileged local user access until systems are patched to prevent local users from triggering the AppArmor large-notification memory leak (e.g., disable unneeded accounts, restrict shell/login access).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47326?
The severity of CVE-2026-47326 is classified as medium with a score of 5.5.
How do I fix CVE-2026-47326?
To fix CVE-2026-47326, it is recommended to upgrade to the latest version of Ubuntu where the vulnerability has been addressed.
What impact does CVE-2026-47326 have on my system?
CVE-2026-47326 can lead to resource exhaustion due to a memory leak when handling large AppArmor notification responses.
Who is affected by CVE-2026-47326?
CVE-2026-47326 affects users running Ubuntu Linux versions 6.8, 6.17, and 7.0.
Can CVE-2026-47326 be exploited by a remote attacker?
CVE-2026-47326 cannot be exploited by a remote attacker as it requires local privileges to trigger the memory leak.