PT-2026-29493 · Linux+2 · Linux Kernel+2

CVE-2026-23410

·

Published

2026-02-24

·

Updated

2026-07-01

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains a race condition within the AppArmor subsystem that can lead to a use-after-free situation. This occurs because rawdata inodes are not properly reference counted, allowing an attacker to manipulate the system such that memory is accessed after it has been freed. Specifically, an attacker can open rawdata files while simultaneously removing the last reference to the rawdata, leading to a dangling pointer in seq rawdata open() and subsequent access to freed memory.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-82034
BDU:2026-07608
CVE-2026-23410
OESA-2026-1862
OESA-2026-1863
OESA-2026-1864
OESA-2026-1950
OESA-2026-2582
OPENSUSE-SU-2026:20826-1
SUSE-SU-2026:2111-1
SUSE-SU-2026:21834-1
SUSE-SU-2026:21841-1
SUSE-SU-2026:21845-1
SUSE-SU-2026:21860-1
SUSE-SU-2026:21876-1
SUSE-SU-2026:21877-1
SUSE-SU-2026:21916-1
SUSE-SU-2026:21919-1
SUSE-SU-2026:2195-1
SUSE-SU-2026:2202-1
SUSE-SU-2026:2215-1
SUSE-SU-2026:2216-1
SUSE-SU-2026:2217-1
SUSE-SU-2026:2238-1
USN-8098-10
USN-8152-1
USN-8163-1
USN-8163-2
USN-8164-1
USN-8165-1
USN-8201-1
USN-8224-1
USN-8243-1
USN-8261-1
USN-8266-1
USN-8267-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu