CVE-2026-47336: Use of uninitialized value in Ubuntu Linux AppArmor IPv4/IPv6 socket mediation rules
Last updated 5 June 2026
Other sources
Ubuntu Linux 6.8 contains SAUCE patches with a possible use of an uninitialized variable in AppArmor AFINET/AFINET6 socket mediation code. The bug can be triggered by an unprivileged local user and could result in incorrect fine-grained mediation of network sockets.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.257-1Fixed in 6.1.170-3Fixed in 6.1.174-1Fixed in 6.12.86-1Fixed in 6.12.90-2Fixed in 7.0.10-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.257-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.170-3 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.174-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.12.86-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.12.90-2 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 7.0.10-1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47336?
The severity of CVE-2026-47336 is classified as low with a score of 3.3.
How do I fix CVE-2026-47336?
To fix CVE-2026-47336, you should update to the latest version of Ubuntu that includes the patched AppArmor socket mediation code.
What impact does CVE-2026-47336 have on system security?
CVE-2026-47336 can potentially allow an unprivileged local user to exploit incorrect mediation of network sockets, affecting fine-grained security controls.
Which versions of Ubuntu are affected by CVE-2026-47336?
CVE-2026-47336 affects Ubuntu Linux 6.8 that includes specific SAUCE patches.
Who can exploit CVE-2026-47336?
CVE-2026-47336 can be exploited by unprivileged local users.