CVE-2026-47333: Out-of-bounds read in Ubuntu Linux AppArmor notification handling
Last updated 5 June 2026
Other sources
Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the AppArmor DFA policy engine.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.257-1Fixed in 6.1.170-3Fixed in 6.1.174-1Fixed in 6.12.86-1Fixed in 6.12.90-2Fixed in 7.0.10-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.257-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.170-3 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.174-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.12.86-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.12.90-2 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 7.0.10-1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47333?
The severity of CVE-2026-47333 is high, with a CVSS score of 7.8.
How do I fix CVE-2026-47333?
To fix CVE-2026-47333, update your Ubuntu system to the latest version that includes the necessary patches for AppArmor.
Who is affected by CVE-2026-47333?
CVE-2026-47333 affects Ubuntu Linux versions 6.8, 6.17, and 7.0 that implement AppArmor.
What are the consequences of CVE-2026-47333?
The consequences of CVE-2026-47333 include potential heap memory out-of-bounds read which can lead to invalid data exposure.
Can CVE-2026-47333 be exploited by unprivileged users?
Yes, CVE-2026-47333 can be triggered by an unprivileged local user.