Junglewise Threat Intelligence

CVE-2026-47333: Ubuntu Linux heap out-of-bounds read in AppArmor SAUCE patches

CVE-2026-47333 · Severity: high · CVSS 7.8 · Published 2026-05-28

Technologies: Ubuntu Linux kernel.

Executive brief

Ubuntu Linux systems using specific kernel versions contain a flaw in AppArmor, a security system that restricts what programs are allowed to do. An attacker with basic access to the system can trigger a memory error that might allow them to bypass security policies or crash the system. This could lead to unauthorized access to sensitive data or a disruption of services.

Technical details

A heap memory out-of-bounds read vulnerability exists in the AppArmor SAUCE patches included in Ubuntu Linux kernels 6.8, 6.17, and 7.0. The flaw is located in the notification handling code, where the system incorrectly computes the size of an internal buffer. An unprivileged local attacker can trigger this bug, causing the AppArmor DFA (Deterministic Finite Automaton) policy engine to process invalid data. This can result in a kernel-level out-of-bounds read (CWE-125), potentially leading to a system crash or the disclosure of sensitive kernel memory. A patch has been identified in the Ubuntu kernel source repository.

Affected products

  • Ubuntu Linux Kernel 6.8, 6.17, 7.0

Timeline

  • 2026-05-28: disclosed: CVE published by Canonical Ltd.

References