CVE-2026-47337: NULL pointer dereference in Ubuntu Linux AppArmor IPv4/IPv6 socket mediation
Last updated 5 June 2026
Other sources
Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AFINET/AFINET6 socket mediation. The bug can be triggered by an unprivileged local user. This can lead to a kernel oops.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.257-1Fixed in 6.1.170-3Fixed in 6.1.174-1Fixed in 6.12.86-1Fixed in 6.12.90-2Fixed in 7.0.10-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.257-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.170-3 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.174-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.12.86-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.12.90-2 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 7.0.10-1 - Compensating control
Until a fixed kernel package is applied, restrict or limit unprivileged local user access to affected systems (for example: remove or disable untrusted local accounts, restrict shell/login access, and apply local ACLs) because the vulnerability can be triggered by an unprivileged local user.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47337?
The severity of CVE-2026-47337 is classified as low with a score of 3.3.
How do I fix CVE-2026-47337?
To fix CVE-2026-47337, upgrade to the latest version of Ubuntu that contains the patches addressing this vulnerability.
What can exploit CVE-2026-47337?
CVE-2026-47337 can be exploited by an unprivileged local user to trigger a NULL pointer dereference.
What is the impact of CVE-2026-47337?
The impact of CVE-2026-47337 is that it may lead to a kernel oops, affecting system stability.
On which versions of Ubuntu does CVE-2026-47337 affect?
CVE-2026-47337 affects Ubuntu Linux versions 6.8, 6.17, and 7.0.