Junglewise Threat Intelligence

CVE-2026-45848: Linux Kernel NULL pointer dereference in AppArmor aa_sock_file_perm

CVE-2026-45848 · Severity: info · CVSS 5.5 · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's AppArmor security module could allow a local user to cause a system crash. AppArmor is a security system that restricts the capabilities of programs to protect the operating system. An attacker could exploit this flaw during specific network socket operations to trigger a 'kernel oops,' leading to a denial of service.

Technical details

A NULL pointer dereference exists in the AppArmor module within the 'aa_sock_file_perm' function in 'security/apparmor/net.c'. The vulnerability occurs because the code fails to validate whether the 'sock' or 'sock->sk' structures are NULL during socket setup or teardown phases. A local attacker can trigger this condition, particularly when using AF_UNIX sockets or older mediation paths, resulting in a kernel oops and denial of service. The fix introduces explicit NULL checks for these structures before they are accessed.

Affected products

  • Linux Linux Kernel All versions since 56974a6fcfef6

Timeline

  • 2025-11-24: patched: Initial patch authored by John Johansen
  • 2026-05-27: disclosed: CVE-2026-45848 published

References