CVE-2026-47328: Invalid pointer deallocation in Ubuntu Linux AppArmor notification handling
Last updated 5 June 2026
Other sources
Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to resource exhaustion.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.257-1Fixed in 6.1.170-3Fixed in 6.1.174-1Fixed in 6.12.86-1Fixed in 6.12.90-2Fixed in 7.0.10-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.257-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.170-3 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.174-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.12.86-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.12.90-2 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 7.0.10-1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47328?
The severity of CVE-2026-47328 is categorized as medium, with a CVSS score of 6.1.
How can I mitigate CVE-2026-47328?
Mitigation of CVE-2026-47328 involves updating Ubuntu Linux to the latest version that addresses the vulnerability.
Who is affected by CVE-2026-47328?
CVE-2026-47328 affects users of Ubuntu Linux versions 6.8, 6.17, and 7.0.
What type of vulnerability is CVE-2026-47328?
CVE-2026-47328 is an invalid pointer deallocation vulnerability in AppArmor notification handling.
Can CVE-2026-47328 be exploited by unprivileged users?
Yes, CVE-2026-47328 can be triggered by an unprivileged local user.