Junglewise Threat Intelligence

CVE-2026-89762: Linux kernel AppArmor credential use-after-free

CVE-2026-89762 · Severity: high · CVSS 7.8 · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

AppArmor is a Linux security module that enforces mandatory access control policies on running applications. A use-after-free vulnerability in AppArmor's credential handling could allow an attacker with local access to trigger a crash or potentially execute code with elevated privileges, affecting system stability and security.

Technical details

The vulnerability is a use-after-free (UAF) in the Linux kernel's AppArmor LSM module, specifically in the begin_current_label_crit_section() function. The root cause is improper handling of credential structures when AppArmor attempts to replace stale labels; if overridden credentials are present, the direct credential replacement can cause reference count mismanagement, leading to freed credential pointers being accessed later. The attack vector is local and requires a process to trigger AppArmor LSM hooks (e.g., via VFS operations or socket calls) while credentials are overridden and a profile update occurs. The fix involves deferring credential replacement to task_work that executes at the end of the current syscall rather than replacing credentials directly during the LSM hook.

Affected products

  • Linux Linux kernel Resolved in later kernel versions

Timeline

  • 2026-09-11: disclosed

Related threats