CVE-2026-47327: NULL pointer dereference in Ubuntu Linux AppArmor notification handling
Last updated 5 June 2026
Other sources
Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.257-1Fixed in 6.1.170-3Fixed in 6.1.174-1Fixed in 6.12.86-1Fixed in 6.12.90-2Fixed in 7.0.10-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.257-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.170-3 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.174-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.12.86-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.12.90-2 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 7.0.10-1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47327?
CVE-2026-47327 has a severity rating of low, with a score of 3.3.
How do I fix CVE-2026-47327?
To address CVE-2026-47327, upgrade to a patched version of the Ubuntu Linux kernel that includes the fix.
What systems are affected by CVE-2026-47327?
CVE-2026-47327 affects Ubuntu Linux versions 6.8, 6.17, and 7.0.
What type of vulnerability is CVE-2026-47327?
CVE-2026-47327 is classified as a Null Pointer Dereference vulnerability.
What can be the impact of exploiting CVE-2026-47327?
Exploitation of CVE-2026-47327 can lead to a kernel oops, potentially causing system instability.