PT-2026-94527 · Linux · Linux Kernel
CVE-2026-90179
·
Published
2026-09-17
·
Updated
2026-09-24
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 6.18.44 through 7.2-rc7
Description
A deadlock occurs in AppArmor when using the
change hat() function while in complain mode. The issue arises when a requested hat does not exist, triggering the creation of a new learning profile via the aa new learning profile() function. Because change hat() already holds the lock to search the hat list, and aa new learning profile() attempts to acquire the same lock to add the new profile to the list, the system enters a deadlock state. This results in the executable hanging and becoming unkillable. Additionally, the issue involves reference count leaks in change hat() and a potential Use-After-Free (UAF) condition during profile lookup when navigating namespace trees.Recommendations
Update the Linux kernel to a version where the locking mechanism in
aa new learning profile() has been refactored to avoid recursive locking during build change hat() calls.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel