Junglewise Threat Intelligence

CVE-2026-72457: Linux kernel AppArmor policy unpack memory allocation error handling

CVE-2026-72457 · Severity: info · Published 2026-08-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

AppArmor is a Linux kernel security module that restricts program capabilities through policy. A bug in policy loading caused the kernel to incorrectly handle allocation failures when preparing security policies, potentially returning incomplete policies that lack required security tables. This could lead to unpredictable security policy enforcement behavior.

Technical details

The vulnerability is a logic error in the unpack_pdb() function within AppArmor's policy_unpack.c module. When allocating the ACCEPT2 table for older policy data fails, the code set an error message but incorrectly jumped to the success path (the "out" label) instead of the failure path, returning a policydb structure with the required ACCEPT2 table missing. The fix ensures that allocation failures return -ENOMEM through the normal error handling path ("fail" label). This is a local kernel code path requiring policy loading, not network-exploitable.

Affected products

  • Linux Linux kernel Multiple versions affected; patch applied across 2.6.11.y through 7.2.y stable branches

Timeline

  • 2026-08-15: disclosed
  • 2026-05-04: patched: Upstream commit 45cf568241048e560a81aa2053f06a62069f5640

References

Related threats