Executive brief
A vulnerability exists in specific versions of the Ubuntu Linux kernel related to how it handles security notifications. An individual with basic access to a system could trigger a kernel crash, leading to a temporary service disruption or system instability. This issue primarily affects system availability rather than the confidentiality or integrity of user data.
Technical details
A NULL pointer dereference vulnerability (CWE-476) exists in the Ubuntu-specific 'SAUCE' patches for the Linux kernel versions 6.8, 6.17, and 7.0. The flaw is located within the AppArmor notification handling mechanism. An unprivileged local attacker can trigger this condition, resulting in a kernel oops (a non-fatal but disruptive kernel panic state). The attack requires local shell access but no elevated privileges. A fix has been identified in the Ubuntu kernel source tree.
Affected products
- Ubuntu Linux Kernel 6.8, 6.17, 7.0
Timeline
- 2026-05-28: disclosed
- 2026-05-28: advisory