PT-2026-29488 · Linux+2 · Linux Kernel+2

CVE-2026-23405

·

Published

2026-04-01

·

Updated

2026-07-01

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a flaw in apparmor where the number of policy namespaces is not bounded, potentially leading to resource exhaustion through arbitrary nesting. This issue is not strictly tied to user namespaces, allowing for the creation and nesting of policy namespaces to an unlimited depth.
Recommendations Limit the depth of policy namespaces to match the depth of user namespaces.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-82019
BDU:2026-07884
CVE-2026-23405
OESA-2026-1862
OESA-2026-1863
OESA-2026-1864
OESA-2026-1950
OPENSUSE-SU-2026:20826-1
SUSE-SU-2026:2068-1
SUSE-SU-2026:2111-1
SUSE-SU-2026:21834-1
SUSE-SU-2026:21841-1
SUSE-SU-2026:21845-1
SUSE-SU-2026:21860-1
SUSE-SU-2026:21876-1
SUSE-SU-2026:21877-1
SUSE-SU-2026:21916-1
SUSE-SU-2026:21919-1
SUSE-SU-2026:2195-1
SUSE-SU-2026:2202-1
SUSE-SU-2026:2215-1
SUSE-SU-2026:2216-1
SUSE-SU-2026:2217-1
SUSE-SU-2026:2238-1
USN-8098-10
USN-8152-1
USN-8163-1
USN-8163-2
USN-8164-1
USN-8165-1
USN-8201-1
USN-8224-1
USN-8243-1
USN-8261-1
USN-8266-1
USN-8267-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu