CVE-2026-47328CWE-590

Invalid pointer deallocation in Ubuntu Linux AppArmor notification handling

Medium · published May 28, 2026

CVSS v3.1
6.1
EPSS
0%
Percentile
0.6
In the wild
Unconfirmed
What it is

Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to resource exhaustion.

The record
Technical detail
CVSS v3.1
6.1 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
CVSS v4.0
Not supplied
EPSS
0.00093 · 0.6th percentile
Weakness
CWE-590 · Free of Memory not on the Heap
Published
2026-05-28T18:27Z
EPSS history
Timeline
  • 28 MAY 18:27Z
    Invalid pointer deallocation in Ubuntu Linux AppArmor notification handling
    cvelistv5