Junglewise Threat Intelligence

CVE-2026-47330: Ubuntu Linux uninitialized variable in AppArmor notification handling

CVE-2026-47330 · Severity: low · CVSS 3.3 · Published 2026-05-28

Executive brief

A security issue has been identified in the Ubuntu Linux kernel's AppArmor component, which is responsible for restricting the capabilities of programs to enhance system security. An unprivileged user on the system could trigger a bug that causes the system to incorrectly remember or cache security decisions. While this does not directly allow for data theft or system crashes, it undermines the integrity of the security enforcement mechanism.

Technical details

The vulnerability is classified as a use of an uninitialized variable (CWE-457) within the AppArmor SAUCE patches integrated into specific Ubuntu Linux kernel versions. The flaw exists in the notification handling code and can be triggered by a local, unprivileged attacker. Successful exploitation results in the incorrect caching of AppArmor notification responses, potentially leading to inconsistent security policy enforcement. A patch has been developed and committed to the Ubuntu kernel source to initialize the affected variable.

Affected products

  • Ubuntu Linux Kernel (Ubuntu) 6.8, 7.0, 7.17

Timeline

  • 2026-05-28: disclosed
  • 2026-05-28: advisory

References