cbcvebase.
CVE-2026-23403
published 2026-04-01

CVE-2026-23403: In the Linux kernel, the following vulnerability has been resolved: apparmor: fix memory leak in verify_header The function sets `*ns = NULL` on every call…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
7.4th percentile
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix memory leak in verify_header The function sets `*ns = NULL` on every call, leaking the namespace string allocated in previous iterations when multiple profiles are unpacked. This also breaks namespace consistency checking since *ns is always NULL when the comparison is made. Remove the incorrect assignment. The caller (aa_unpack) initializes *ns to NULL once before the loop, which is sufficient.

Affected

43 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
linuxlinux
linuxlinux>= dd51c84857630e77c139afe4d9bba65fc051dc3f < 9d678eb0fe55c9195d9a253e8c5b82a87b9307379d678eb0fe55c9195d9a253e8c5b82a87b930737
linuxlinux>= dd51c84857630e77c139afe4d9bba65fc051dc3f < 6b79abcb3c985e153fcf9d395e1d4336081aabc26b79abcb3c985e153fcf9d395e1d4336081aabc2
linuxlinux>= dd51c84857630e77c139afe4d9bba65fc051dc3f < bcf82c0c5a8b383fd2d5d8f3fd880cdcab2ac557bcf82c0c5a8b383fd2d5d8f3fd880cdcab2ac557
linuxlinux>= dd51c84857630e77c139afe4d9bba65fc051dc3f < 663ce34786e759ebcbeb3060685c20bcc886d51a663ce34786e759ebcbeb3060685c20bcc886d51a
linuxlinux>= dd51c84857630e77c139afe4d9bba65fc051dc3f < 786e2c2a87d9c505f33321d1fd23a176aa8ddeb1786e2c2a87d9c505f33321d1fd23a176aa8ddeb1
linuxlinux>= dd51c84857630e77c139afe4d9bba65fc051dc3f < 4f0889f2df1ab99224a5e1ac4e20437eea5fe38e4f0889f2df1ab99224a5e1ac4e20437eea5fe38e
linuxlinux>= dd51c84857630e77c139afe4d9bba65fc051dc3f < 42fd831abfc15d0643c14688f0522556b347e7e642fd831abfc15d0643c14688f0522556b347e7e6
linuxlinux>= dd51c84857630e77c139afe4d9bba65fc051dc3f < e38c55d9f834e5b848bfed0f5c586aaf45acb825e38c55d9f834e5b848bfed0f5c586aaf45acb825
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.251-15.10.251-1
linuxlinux_kernel>= 0 < 6.1.164-16.1.164-1
linuxlinux_kernel>= 0 < 6.12.74-26.12.74-2
linuxlinux_kernel>= 0 < 6.19.6-26.19.6-2
linuxlinux_kernel>= 3.12.1 < 5.10.2535.10.253
linuxlinux_kernel>= 5.11 < 5.15.2035.15.203
linuxlinux_kernel>= 5.16 < 6.1.1696.1.169
linuxlinux_kernel>= 6.13 < 6.18.186.18.18
linuxlinux_kernel>= 6.19 < 6.19.86.19.8
linuxlinux_kernel>= 6.2 < 6.6.1306.6.130
linuxlinux_kernel>= 6.7 < 6.12.776.12.77
ubuntulinux
ubuntulinux-aws

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.2HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.