CVE-2026-93245: apparmor: policy_int make sure list heads are initialized before fail path

Published Sep 24, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

apparmor: policyint make sure list heads are initialized before fail path

If profile create fails before policyinit is complete the list heads are not properly initialized causing profilefree() sanity checks to trigger the following splat.

AppArmor WARN aapolicydestroy: (((!listempty(&policy->profiles) && (&policy->profiles)->prev != ((void ) 0x122 + (0xdead000000000000UL))))): WARNING: security/apparmor/lib.c:509 at aapolicydestroy+0x164/0x1b0 security/apparmor/lib.c:509, CPU#0: syz.0.17/5541 Modules linked in: CPU: 0 UID: 0 PID: 5541 Comm: syz.0.17 Not tainted syzkaller #0 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 RIP: 0010:aapolicydestroy+0x16b/0x1b0 security/apparmor/lib.c:509 Code: 85 ed 7e 4d e8 96 bc 37 fd 5b 41 5c 41 5e 41 5f 5d e9 19 27 4e 07 cc e8 83 bc 37 fd 48 8d 3d 0c f0 d3 0b 48 c7 c6 a4 eb 38 8e <67> 48 0f b9 3a e9 04 ff ff ff e8 66 bc 37 fd 48 8d 3d ff ef d3 0b RSP: 0018:ffffc9000345eaa0 EFLAGS: 00010293 RAX: ffffffff848f530d RBX: ffff88803f734800 RCX: ffff88801af2a580 RDX: 0000000000000000 RSI: ffffffff8e38eba4 RDI: ffffffff90634320 RBP: 0000000000000000 R08: 0000000000000cc0 R09: 00000000ffffffff R10: dffffc0000000000 R11: fffffbfff1d95913 R12: dead000000000122 R13: ffff88803f734800 R14: ffff88803f734828 R15: dffffc0000000000 FS: 00007f5f6a1836c0(0000) GS:ffff88808c519000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 000055d02407b048 CR3: 0000000012aa9000 CR4: 0000000000352ef0 Call Trace: <TASK> aafreeprofile+0x9d/0x9f0 security/apparmor/policy.c:334 aaallocprofile+0x1e4/0x3e0 security/apparmor/policy.c:416 unpackprofile security/apparmor/policyunpack.c:1153 [inline] aaunpack+0x17db/0x7430 security/apparmor/policyunpack.c:1748 aareplaceprofiles+0x226/0x2a20 security/apparmor/policy.c:1183 policyupdate+0x234/0x4a0 security/apparmor/apparmorfs.c:505 profileload+0x1cb/0x320 security/apparmor/apparmorfs.c:522 vfswrite+0x296/0xba0 fs/readwrite.c:685 ksyswrite+0x150/0x270 fs/readwrite.c:739 dosyscallx64 arch/x86/entry/syscall64.c:61 [inline] dosyscall64+0x166/0x520 arch/x86/entry/syscall64.c:84 entrySYSCALL64afterhwframe+0x77/0x7f RIP: 0033:0x7f5f6939e0d9 Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007f5f6a183028 EFLAGS: 00000246 ORIGRAX: 0000000000000001 RAX: ffffffffffffffda RBX: 00007f5f69625fa0 RCX: 00007f5f6939e0d9 RDX: 0000000000000041 RSI: 0000200000000400 RDI: 0000000000000003 RBP: 00007f5f6a183090 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001 R13: 00007f5f69626038 R14: 00007f5f69625fa0 R15: 00007ffe23725c18

Affected Software

1 affected component
Linux Linux kernel

Event History

Sep 24, 2026
CVE Published
via MITRE·03:51 PM
Data Sourced
via MITRE·03:51 PM
Description
Data Sourced
via NVD·04:17 PM
Description

Frequently Asked Questions

1

What condition triggers the warning?

The warning occurs when AppArmor profile creation fails before policy initialization has completed. In that path, profile_free() reaches aa_policy_destroy() with uninitialized policy list heads, causing its sanity checks to trigger.

2

How can I recognize that a system has encountered this issue?

Kernel logs show an AppArmor warning from aa_policy_destroy at security/apparmor/lib.c:509, with a failed list_empty(&policy->profiles) sanity check. The reported call site is aa_policy_destroy+0x164/0x1b0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203