Junglewise Threat Intelligence

CVE-2026-89761: Linux kernel AppArmor out-of-bounds write in label parsing

CVE-2026-89761 · Severity: high · CVSS 7.8 · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

AppArmor is a mandatory access control system in the Linux kernel that enforces security policies. A vulnerability in label parsing can cause an out-of-bounds write, potentially allowing an unprivileged user to corrupt kernel memory and compromise system stability or security. This can be triggered through writing to a proc file or by calling a system function available to any user.

Technical details

The vulnerability is an out-of-bounds write in the AppArmor label parsing code. The root cause is that aa_vec_unique() writes a null terminator at position vec[n] when VEC_FLAG_TERMINATE is set and no duplicates are found, but vec_setup() does not allocate space for this terminator entry. When aa_label_strn_parse() calls aa_vec_unique() on a vector allocated by vec_setup(), the terminator overwrites memory beyond the allocated buffer. The attack vector is unprivileged: any user can trigger this by writing to /proc/self/attr/apparmor/current, through lsm_set_self_attr(2), or by accessing the securityfs .access file (mode 0666). The attacker must have a system with AppArmor policy loaded. The fix is to reserve space for the null terminator in vec_setup() and DEFINE_VEC().

Affected products

  • Linux Linux kernel various (vulnerability introduced in AppArmor subsystem)

Timeline

  • 2026-09-11: disclosed

Related threats