cbcvebase.
CVE-2026-23407
published 2026-04-01

CVE-2026-23407: In the Linux kernel, the following vulnerability has been resolved: apparmor: fix missing bounds check on DEFAULT table in verify_dfa() The verify_dfa()…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.18%
7.9th percentile
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix missing bounds check on DEFAULT table in verify_dfa() The verify_dfa() function only checks DEFAULT_TABLE bounds when the state is not differentially encoded. When the verification loop traverses the differential encoding chain, it reads k = DEFAULT_TABLE[j] and uses k as an array index without validation. A malformed DFA with DEFAULT_TABLE[j] >= state_count, therefore, causes both out-of-bounds reads and writes. [ 57.179855] ================================================================== [ 57.180549] BUG: KASAN: slab-out-of-bounds in verify_dfa+0x59a/0x660 [ 57.180904] Read of size 4 at addr ffff888100eadec4 by task su/993 [ 57.181554] CPU: 1 UID: 0 PID: 993 Comm: su Not tainted 6.19.0-rc7-next-20260127 #1 PREEMPT(lazy) [ 57.181558] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 57.181563] Call Trace: [ 57.181572] [ 57.181577] dump_stack_lvl+0x5e/0x80 [ 57.181596] print_report+0xc8/0x270 [ 57.181605] ? verify_dfa+0x59a/0x660 [ 57.181608] kasan_report+0x118/0x150 [ 57.181620] ? verify_dfa+0x59a/0x660 [ 57.181623] verify_dfa+0x59a/0x660 [ 57.181627] aa_dfa_unpack+0x1610/0x1740 [ 57.181629] ? __kmalloc_cache_noprof+0x1d0/0x470 [ 57.181640] unpack_pdb+0x86d/0x46b0 [ 57.181647] ? srso_alias_return_thunk+0x5/0xfbef5 [ 57.181653] ? srso_alias_return_thunk+0x5/0xfbef5 [ 57.181656] ? aa_unpack_nameX+0x1a8/0x300 [ 57.181659] aa_unpack+0x20b0/0x4c30 [ 57.181662] ? srso_alias_return_thunk+0x5/0xfbef5 [ 57.181664] ? stack_depot_save_flags+0x33/0x700 [ 57.181681] ? kasan_save_track+0x4f/0x80 [ 57.181683] ? kasan_save_track+0x3e/0x80 [ 57.181686] ? __kasan_kmalloc+0x93/0xb0 [ 57.181688] ? __kvmalloc_node_noprof+0x44a/0x780 [ 57.181693] ? aa_simple_write_to_buffer+0x54/0x130 [ 57.181697] ? policy_update+0x154/0x330 [ 57.181704] aa_replace_profiles+0x15a/0x1dd0 [ 57.181707] ? srso_alias_return_thunk+0x5/0xfbef5 [ 57.181710] ? __kvmalloc_node_noprof

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
linuxlinux
linuxlinux>= 031dcc8f4e84fea37dc6f78fdc7288aa7f8386c3 < 555829fd91eaf0711e369b0a92aecb0f0aa3281f555829fd91eaf0711e369b0a92aecb0f0aa3281f
linuxlinux>= 031dcc8f4e84fea37dc6f78fdc7288aa7f8386c3 < a75e12ca90c9e70ba10fee1be2f63cdd63d91a7ca75e12ca90c9e70ba10fee1be2f63cdd63d91a7c
linuxlinux>= 031dcc8f4e84fea37dc6f78fdc7288aa7f8386c3 < 22094c996968a7c5b59cd3fc9fcbdfdd46d02fec22094c996968a7c5b59cd3fc9fcbdfdd46d02fec
linuxlinux>= 031dcc8f4e84fea37dc6f78fdc7288aa7f8386c3 < 7c7cf05e0606f554c467e3a4dc49e2e578a755b47c7cf05e0606f554c467e3a4dc49e2e578a755b4
linuxlinux>= 031dcc8f4e84fea37dc6f78fdc7288aa7f8386c3 < 76b4d36c5122866452d34d8f79985e191f9c383176b4d36c5122866452d34d8f79985e191f9c3831
linuxlinux>= 031dcc8f4e84fea37dc6f78fdc7288aa7f8386c3 < 5a68e46dfe0c8c8ffc6f425ebc4cae6238566ecc5a68e46dfe0c8c8ffc6f425ebc4cae6238566ecc
linuxlinux>= 031dcc8f4e84fea37dc6f78fdc7288aa7f8386c3 < f39e126e56c6ec1930fae51ad6bca3dae2a4c3edf39e126e56c6ec1930fae51ad6bca3dae2a4c3ed
linuxlinux>= 031dcc8f4e84fea37dc6f78fdc7288aa7f8386c3 < d352873bbefa7eb39995239d0b44ccdf8aaa79a4d352873bbefa7eb39995239d0b44ccdf8aaa79a4
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.251-15.10.251-1
linuxlinux_kernel>= 0 < 6.1.164-16.1.164-1
linuxlinux_kernel>= 0 < 6.12.74-26.12.74-2
linuxlinux_kernel>= 0 < 6.19.6-26.19.6-2
linuxlinux_kernel>= 4.17.1 < 5.10.2535.10.253
linuxlinux_kernel>= 5.11 < 5.15.2035.15.203
linuxlinux_kernel>= 5.16 < 6.1.1696.1.169
linuxlinux_kernel>= 6.13 < 6.18.186.18.18
linuxlinux_kernel>= 6.19 < 6.19.86.19.8
linuxlinux_kernel>= 6.2 < 6.6.1306.6.130
linuxlinux_kernel>= 6.7 < 6.12.776.12.77
ubuntulinux-azure-5.15
ubuntulinux-azure-5.4

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.