cbcvebase.
CVE-2026-23406
published 2026-04-01

CVE-2026-23406: In the Linux kernel, the following vulnerability has been resolved: apparmor: fix side-effect bug in match_char() macro usage The match_char() macro evaluates…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.18%
7.4th percentile
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix side-effect bug in match_char() macro usage The match_char() macro evaluates its character parameter multiple times when traversing differential encoding chains. When invoked with *str++, the string pointer advances on each iteration of the inner do-while loop, causing the DFA to check different characters at each iteration and therefore skip input characters. This results in out-of-bounds reads when the pointer advances past the input buffer boundary. [ 94.984676] ================================================================== [ 94.985301] BUG: KASAN: slab-out-of-bounds in aa_dfa_match+0x5ae/0x760 [ 94.985655] Read of size 1 at addr ffff888100342000 by task file/976 [ 94.986319] CPU: 7 UID: 1000 PID: 976 Comm: file Not tainted 6.19.0-rc7-next-20260127 #1 PREEMPT(lazy) [ 94.986322] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 94.986329] Call Trace: [ 94.986341] [ 94.986347] dump_stack_lvl+0x5e/0x80 [ 94.986374] print_report+0xc8/0x270 [ 94.986384] ? aa_dfa_match+0x5ae/0x760 [ 94.986388] kasan_report+0x118/0x150 [ 94.986401] ? aa_dfa_match+0x5ae/0x760 [ 94.986405] aa_dfa_match+0x5ae/0x760 [ 94.986408] __aa_path_perm+0x131/0x400 [ 94.986418] aa_path_perm+0x219/0x2f0 [ 94.986424] apparmor_file_open+0x345/0x570 [ 94.986431] security_file_open+0x5c/0x140 [ 94.986442] do_dentry_open+0x2f6/0x1120 [ 94.986450] vfs_open+0x38/0x2b0 [ 94.986453] ? may_open+0x1e2/0x2b0 [ 94.986466] path_openat+0x231b/0x2b30 [ 94.986469] ? __x64_sys_openat+0xf8/0x130 [ 94.986477] do_file_open+0x19d/0x360 [ 94.986487] do_sys_openat2+0x98/0x100 [ 94.986491] __x64_sys_openat+0xf8/0x130 [ 94.986499] do_syscall_64+0x8e/0x660 [ 94.986515] ? count_memcg_events+0x15f/0x3c0 [ 94.986526] ? srso_alias_return_thunk+0x5/0xfbef5 [ 94.986540] ? handle_mm_fault+0x1639/0x1ef0 [ 94.986551] ? vma_start_read+0xf0/0x320 [ 94.986558] ? srso_alias_return_thunk+0x5/0xfbef5 [ 94.986561

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
linuxlinux
linuxlinux>= 074c1cd798cb0b481d7eaa749b64aa416563c053 < c7dc56d8b37eda1396feeec3ab1c7ecee5eae31bc7dc56d8b37eda1396feeec3ab1c7ecee5eae31b
linuxlinux>= 074c1cd798cb0b481d7eaa749b64aa416563c053 < f16f2e5936c0f5f0d11fdf10d2be3e47e7108e42f16f2e5936c0f5f0d11fdf10d2be3e47e7108e42
linuxlinux>= 074c1cd798cb0b481d7eaa749b64aa416563c053 < 1fc94f16098213d01e56c97feed9b3ecf0147a371fc94f16098213d01e56c97feed9b3ecf0147a37
linuxlinux>= 074c1cd798cb0b481d7eaa749b64aa416563c053 < 5a184f7cbdeaad17e16dedf3c17d0cd622edfed85a184f7cbdeaad17e16dedf3c17d0cd622edfed8
linuxlinux>= 074c1cd798cb0b481d7eaa749b64aa416563c053 < b73c1dff8a9d7eeaebabf8097a5b2de192f40913b73c1dff8a9d7eeaebabf8097a5b2de192f40913
linuxlinux>= 074c1cd798cb0b481d7eaa749b64aa416563c053 < 0510d1ba0976f97f521feb2b75b0572ea5df3ceb0510d1ba0976f97f521feb2b75b0572ea5df3ceb
linuxlinux>= 074c1cd798cb0b481d7eaa749b64aa416563c053 < 383b7270faf42564f133134c2fc3c24bbae52615383b7270faf42564f133134c2fc3c24bbae52615
linuxlinux>= 074c1cd798cb0b481d7eaa749b64aa416563c053 < 8756b68edae37ff546c02091989a4ceab3f20abd8756b68edae37ff546c02091989a4ceab3f20abd
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.251-15.10.251-1
linuxlinux_kernel>= 0 < 6.1.164-16.1.164-1
linuxlinux_kernel>= 0 < 6.12.74-26.12.74-2
linuxlinux_kernel>= 0 < 6.19.6-26.19.6-2
linuxlinux_kernel>= 4.17.1 < 5.10.2535.10.253
linuxlinux_kernel>= 5.11 < 5.15.2035.15.203
linuxlinux_kernel>= 5.16 < 6.1.1696.1.169
linuxlinux_kernel>= 6.13 < 6.18.186.18.18
linuxlinux_kernel>= 6.19 < 6.19.86.19.8
linuxlinux_kernel>= 6.2 < 6.6.1306.6.130
linuxlinux_kernel>= 6.7 < 6.12.776.12.77
ubuntulinux-azure-5.15
ubuntulinux-azure-5.4

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.