cbcvebase.
CVE-2026-23408
published 2026-04-01

CVE-2026-23408: In the Linux kernel, the following vulnerability has been resolved: apparmor: Fix double free of ns_name in aa_replace_profiles() if ns_name is NULL after 1071…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.18%
8.0th percentile
In the Linux kernel, the following vulnerability has been resolved: apparmor: Fix double free of ns_name in aa_replace_profiles() if ns_name is NULL after 1071 error = aa_unpack(udata, &lh, &ns_name); and if ent->ns_name contains an ns_name in 1089 } else if (ent->ns_name) { then ns_name is assigned the ent->ns_name 1095 ns_name = ent->ns_name; however ent->ns_name is freed at 1262 aa_load_ent_free(ent); and then again when freeing ns_name at 1270 kfree(ns_name); Fix this by NULLing out ent->ns_name after it is transferred to ns_name ")

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
linuxlinux
linuxlinux>= 145a0ef21c8e944957f58e2c8ffcd8a10f46266a < c6347a2116ecccb8fd9ee4ebc75ae41d1d7ef689c6347a2116ecccb8fd9ee4ebc75ae41d1d7ef689
linuxlinux>= 145a0ef21c8e944957f58e2c8ffcd8a10f46266a < c053ae381ce227577567d1ef10090ce7506d7a28c053ae381ce227577567d1ef10090ce7506d7a28
linuxlinux>= 145a0ef21c8e944957f58e2c8ffcd8a10f46266a < 35f4caec1352054b9a61cfdf2bf1898073637aa035f4caec1352054b9a61cfdf2bf1898073637aa0
linuxlinux>= 145a0ef21c8e944957f58e2c8ffcd8a10f46266a < 55ef2af7490aaf72f8ffe11ec44c6bcb7eb2162a55ef2af7490aaf72f8ffe11ec44c6bcb7eb2162a
linuxlinux>= 145a0ef21c8e944957f58e2c8ffcd8a10f46266a < 86feeccd6b93ed94bd6655f30de80f163f8d5a4586feeccd6b93ed94bd6655f30de80f163f8d5a45
linuxlinux>= 145a0ef21c8e944957f58e2c8ffcd8a10f46266a < 7998ab3010d2317643f91828f1853d954ef313877998ab3010d2317643f91828f1853d954ef31387
linuxlinux>= 145a0ef21c8e944957f58e2c8ffcd8a10f46266a < 18b5233e860c294a847ee07869d93c0b8673a54b18b5233e860c294a847ee07869d93c0b8673a54b
linuxlinux>= 145a0ef21c8e944957f58e2c8ffcd8a10f46266a < 5df0c44e8f5f619d3beb871207aded7c784145025df0c44e8f5f619d3beb871207aded7c78414502
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.251-15.10.251-1
linuxlinux_kernel>= 0 < 6.1.164-16.1.164-1
linuxlinux_kernel>= 0 < 6.12.74-26.12.74-2
linuxlinux_kernel>= 0 < 6.19.6-26.19.6-2
linuxlinux_kernel>= 5.11 < 5.15.2035.15.203
linuxlinux_kernel>= 5.16 < 6.1.1696.1.169
linuxlinux_kernel>= 5.5.1 < 5.10.2535.10.253
linuxlinux_kernel>= 6.13 < 6.18.186.18.18
linuxlinux_kernel>= 6.19 < 6.19.86.19.8
linuxlinux_kernel>= 6.2 < 6.6.1306.6.130
linuxlinux_kernel>= 6.7 < 6.12.776.12.77
ubuntulinux-azure-5.15
ubuntulinux-azure-5.4

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.