Executive brief
A vulnerability in the Linux kernel's AppArmor security module could allow a local user to cause a system crash. AppArmor is a security system that restricts the capabilities of programs to protect the operating system. An attacker could exploit this flaw during specific network socket operations to trigger a 'kernel oops,' leading to a denial of service.
Technical details
A NULL pointer dereference exists in the AppArmor module within the 'aa_sock_file_perm' function in 'security/apparmor/net.c'. The vulnerability occurs because the code fails to validate whether the 'sock' or 'sock->sk' structures are NULL during socket setup or teardown phases. A local attacker can trigger this condition, particularly when using AF_UNIX sockets or older mediation paths, resulting in a kernel oops and denial of service. The fix introduces explicit NULL checks for these structures before they are accessed.
Affected products
- Linux Linux Kernel All versions since 56974a6fcfef6
Timeline
- 2025-11-24: patched: Initial patch authored by John Johansen
- 2026-05-27: disclosed: CVE-2026-45848 published
References
- https://git.kernel.org/stable/c/00b67657535dfea56e84d11492f5c0f61d0af297
- https://git.kernel.org/stable/c/0dc19bca22606f7a61d5988408f74e3ae0ef3486
- https://git.kernel.org/stable/c/3852eb9a0392eb435c03dcb47d581bcfe6a9a95b
- https://git.kernel.org/stable/c/5121b7283f1c46e4c06b88b1dda7b064429d77de
- https://git.kernel.org/stable/c/68538ec34fcb4194c7961dc4eca6f5537fec8067
- https://git.kernel.org/stable/c/8a0ededbfcff74598f82f1d4b8ef9db28878b317
- https://git.kernel.org/stable/c/c11b7c3280d000376e27ebfed17ec7046699eab4