Executive brief
A security flaw in the Ubuntu Linux kernel's AppArmor component could allow a local user to crash the system or cause it to run out of memory. AppArmor is a security module that restricts the capabilities of programs to protect the operating system. An attacker with basic access to the system can exploit this bug to disrupt operations and impact service availability.
Technical details
This vulnerability is a 'Free of Memory not on the Heap' (CWE-590) issue within the AppArmor SAUCE patches in specific Ubuntu Linux kernel versions. The root cause is an incorrect attempt to free a pointer that was not allocated via kmalloc(), combined with a simultaneous memory leak. An unprivileged local attacker can trigger this bug to corrupt slab metadata or cause resource exhaustion. This can lead to a denial-of-service (DoS) condition through system instability or memory depletion. A patch has been identified in the Ubuntu kernel source tree.
Affected products
- Ubuntu Linux Kernel 6.8, 6.17, 7.0
Timeline
- 2026-05-28: disclosed
- 2026-05-28: advisory