Junglewise Threat Intelligence

CVE-2026-46328: Linux kernel AppArmor incorrect resource limit in POSIX CPU timers

CVE-2026-46328 · Severity: info · CVSS 3.3 · Published 2026-06-09

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's AppArmor security module where CPU resource limits were not being correctly applied to certain types of timers. This could allow a restricted process to consume more processor time than intended by system administrators. While this does not lead to data theft, it could potentially be used to cause performance degradation or a partial denial of service on the affected system.

Technical details

A vulnerability in the AppArmor security module's resource limit (rlimit) handling was discovered in the Linux kernel. Specifically, when transitioning between security labels, AppArmor updated the RLIMIT_CPU value but failed to perform the additional necessary step of calling update_rlimit_cpu() for POSIX CPU timers. This oversight meant that even if a new AppArmor profile imposed stricter CPU limits, the underlying POSIX timers would not be updated to reflect these changes. An attacker with local access could potentially exploit this to bypass CPU resource constraints. The issue was resolved by refactoring __aa_transition_rlimits in security/apparmor/resource.c to conditionally update POSIX CPU timers when RLIMIT_CPU is modified.

Affected products

  • Linux Linux kernel All versions prior to the 2026 patches

Timeline

  • 2025-11-09: other: Initial fix authored by John Johansen
  • 2026-06-09: disclosed: CVE-2026-46328 published

References

Related threats