CVE-2026-47334: Deadlock or kernel panic in Ubuntu Linux AppArmor notification handling
Last updated 5 June 2026
Other sources
Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user and can result in kernel panic or deadlock.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.257-1Fixed in 6.1.170-3Fixed in 6.1.174-1Fixed in 6.12.86-1Fixed in 6.12.90-2Fixed in 7.0.10-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.257-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.170-3 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.174-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.12.86-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.12.90-2 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 7.0.10-1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47334?
The severity of CVE-2026-47334 is medium with a score of 5.5.
What are the potential impacts of CVE-2026-47334?
CVE-2026-47334 can lead to kernel panic or deadlock when triggered by an unprivileged local user.
How do I fix CVE-2026-47334?
To fix CVE-2026-47334, apply the latest patches provided by Ubuntu for versions 6.8, 6.17, and 7.0.
Which versions of Ubuntu are affected by CVE-2026-47334?
CVE-2026-47334 affects Ubuntu Linux versions 6.8, 6.17, and 7.0.
Can CVE-2026-47334 be exploited remotely?
No, CVE-2026-47334 requires local access to the system to exploit.