CVE-2026-47329
Analyzed
Analyzed - Analysis Complete
AppArmor Notification Size Validation Flaw in Ubuntu Linux
Publication date: 2026-05-28
Last updated on: 2026-06-09
Assigner: Canonical Ltd.
Description
Description
Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| canonical | ubuntu_linux | 24.04 |
| canonical | ubuntu_linux | 25.10 |
| canonical | ubuntu_linux | 26.04 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1284 | The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties. |