Executive brief
AppArmor is a Linux security module that enforces mandatory access control policies on running applications. A use-after-free vulnerability in AppArmor's credential handling could allow an attacker with local access to trigger a crash or potentially execute code with elevated privileges, affecting system stability and security.
Technical details
The vulnerability is a use-after-free (UAF) in the Linux kernel's AppArmor LSM module, specifically in the begin_current_label_crit_section() function. The root cause is improper handling of credential structures when AppArmor attempts to replace stale labels; if overridden credentials are present, the direct credential replacement can cause reference count mismanagement, leading to freed credential pointers being accessed later. The attack vector is local and requires a process to trigger AppArmor LSM hooks (e.g., via VFS operations or socket calls) while credentials are overridden and a profile update occurs. The fix involves deferring credential replacement to task_work that executes at the end of the current syscall rather than replacing credentials directly during the LSM hook.
Affected products
- Linux Linux kernel Resolved in later kernel versions
Timeline
- 2026-09-11: disclosed