cbcvebase.
CVE-2026-23404
published 2026-04-01

CVE-2026-23404: In the Linux kernel, the following vulnerability has been resolved: apparmor: replace recursive profile removal with iterative approach The profile removal…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
7.4th percentile
In the Linux kernel, the following vulnerability has been resolved: apparmor: replace recursive profile removal with iterative approach The profile removal code uses recursion when removing nested profiles, which can lead to kernel stack exhaustion and system crashes. Reproducer: $ pf='a'; for ((i=0; i /sys/kernel/security/apparmor/.remove Replace the recursive __aa_profile_list_release() approach with an iterative approach in __remove_profile(). The function repeatedly finds and removes leaf profiles until the entire subtree is removed, maintaining the same removal semantic without recursion.

Affected

43 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
linuxlinux
linuxlinux>= c88d4c7b049e87998ac0a9f455aa545cc895ef92 < ea854f032190cc9f26dc4a0e727090c89e55e342ea854f032190cc9f26dc4a0e727090c89e55e342
linuxlinux>= c88d4c7b049e87998ac0a9f455aa545cc895ef92 < 4fdc847b107321dec22bf8ecd6019b7af76d78864fdc847b107321dec22bf8ecd6019b7af76d7886
linuxlinux>= c88d4c7b049e87998ac0a9f455aa545cc895ef92 < b36a04284d0208be94e5e401409caa00e2bf1be1b36a04284d0208be94e5e401409caa00e2bf1be1
linuxlinux>= c88d4c7b049e87998ac0a9f455aa545cc895ef92 < 33959a491e9fd557abfa5fce5ae4637d400915d333959a491e9fd557abfa5fce5ae4637d400915d3
linuxlinux>= c88d4c7b049e87998ac0a9f455aa545cc895ef92 < 999bd704b0b641527a5ed46f0d969deff8cfa68b999bd704b0b641527a5ed46f0d969deff8cfa68b
linuxlinux>= c88d4c7b049e87998ac0a9f455aa545cc895ef92 < 7eade846e013cbe8d2dc4a484463aa19e6515c7f7eade846e013cbe8d2dc4a484463aa19e6515c7f
linuxlinux>= c88d4c7b049e87998ac0a9f455aa545cc895ef92 < a6a941a1294ac5abe22053dc501d25aed96e48fea6a941a1294ac5abe22053dc501d25aed96e48fe
linuxlinux>= c88d4c7b049e87998ac0a9f455aa545cc895ef92 < ab09264660f9de5d05d1ef4e225aa447c63a8747ab09264660f9de5d05d1ef4e225aa447c63a8747
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.251-15.10.251-1
linuxlinux_kernel>= 0 < 6.1.164-16.1.164-1
linuxlinux_kernel>= 0 < 6.12.74-26.12.74-2
linuxlinux_kernel>= 0 < 6.19.6-26.19.6-2
linuxlinux_kernel>= 2.6.36.1 < 5.10.2535.10.253
linuxlinux_kernel>= 5.11 < 5.15.2035.15.203
linuxlinux_kernel>= 5.16 < 6.1.1696.1.169
linuxlinux_kernel>= 6.13 < 6.18.186.18.18
linuxlinux_kernel>= 6.19 < 6.19.86.19.8
linuxlinux_kernel>= 6.2 < 6.6.1306.6.130
linuxlinux_kernel>= 6.7 < 6.12.776.12.77
ubuntulinux
ubuntulinux-aws

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.2HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.