Junglewise Threat Intelligence

CVE-2026-63827: Linux Kernel AppArmor use-after-free in rawdata dedup loop

CVE-2026-63827 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's AppArmor security module, which is responsible for restricting the capabilities of programs to enhance system security. A flaw in how the system manages internal security profiles could lead to a 'use-after-free' condition, potentially causing system instability or crashes. This issue occurs during the process of updating or deduplicating security policies, which could impact the overall reliability of the system's security enforcement.

Technical details

A use-after-free vulnerability exists in the AppArmor component of the Linux kernel. The function aa_replace_profiles() iterates through ns->rawdata_list to deduplicate incoming policy blobs. Because list membership does not hold a reference count (pcount), an entry can remain on the list with a refcount of zero after its last profile reference is dropped but before the deferred cleanup workqueue (do_ploaddata_rmfs) runs. The code incorrectly used aa_get_profile_loaddata(), which performs an unconditional kref_get(), leading to refcount hardening warnings or use-after-free conditions when hitting these 'dying' entries. The fix introduces aa_get_profile_loaddata_not0() to ensure references are only taken on active entries. The vulnerability is reachable via local stress testing of AppArmor policy loading.

Affected products

  • Linux Linux Kernel v7.1-rc5 and earlier versions including 6.x stable branches

Timeline

  • 2026-05-26: disclosed: Initial patch authored
  • 2026-07-04: patched: Patch committed to stable branches
  • 2026-07-19: advisory: NVD publication date

References

Related threats