CVE-2026-23410Improper Update of Reference Count in Linux

Severity
7.8HIGHNVD
OSV7.2
EPSS
0.0%
top 97.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 1
Latest updateApr 19

Description

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race on rawdata dereference There is a race condition that leads to a use-after-free situation: because the rawdata inodes are not refcounted, an attacker can start open()ing one of the rawdata files, and at the same time remove the last reference to this rawdata (by removing the corresponding profile, for example), which frees its struct aa_loaddata; as a result, when seq_rawdata_open() is reached, i_private is

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

Debianlinux/linux_kernel< 5.10.251-1+3
CVEListV5linux/linux5d5182cae40115c03933989473288e54afb39c7c6ef1f2926c41ab96952d9696d55a052f1b3a9418+5
debiandebian/linux< linux 6.1.164-1 (bookworm)

🔴Vulnerability Details

5
VulDB
Linux Kernel up to 7.0-rc3 apparmor use after free (EUVD-2026-17841)2026-04-19
OSV
linux-oem-6.17 vulnerabilities2026-04-06
OSV
CVE-2026-23410: In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race on rawdata dereference There is a race condition that leads to2026-04-01
GHSA
GHSA-cgmp-3cx7-qfjw: In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race on rawdata dereference There is a race condition that leads t2026-04-01
CVEList
apparmor: fix race on rawdata dereference2026-04-01

📋Vendor Advisories

7
Ubuntu
Linux kernel (Azure) vulnerabilities2026-04-13
Ubuntu
Linux kernel (Azure FIPS) vulnerabilities2026-04-09
Ubuntu
Linux kernel (Azure FIPS) vulnerabilities2026-04-09
Ubuntu
Linux kernel (Intel IoTG Real-time) vulnerabilities2026-04-09
Ubuntu
Linux kernel (OEM) vulnerabilities2026-04-06

🕵️Threat Intelligence

1
Wiz
CVE-2026-23410 Impact, Exploitability, and Mitigation Steps | Wiz