Executive brief
A security vulnerability has been identified in Ubuntu Linux 6.8 involving the AppArmor security framework. This flaw allows a standard user on the system to potentially crash the computer or gain unauthorized administrative control. This could lead to a total compromise of the system's data and operations by an internal user or an attacker who has already gained a foothold on the machine.
Technical details
A race condition exists in the Ubuntu-specific 'SAUCE' patches for AppArmor in Linux kernel 6.8. The vulnerability stems from a failure to acquire a necessary lock when modifying a linked list structure. An unprivileged local attacker can exploit this race condition to trigger a use-after-free (UAF) memory corruption. Successful exploitation could allow for arbitrary code execution with kernel privileges or cause a system crash (denial of service). A fix has been identified in the Ubuntu kernel source tree.
Affected products
- Ubuntu Linux Kernel 6.8 6.8 (specifically Noble Numbat)
Timeline
- 2026-05-28: disclosed
- 2026-05-28: advisory