CVE-2026-47330
AppArmor Notification Handling Uninitialized Variable in Ubuntu Linux
Publication date: 2026-05-28
Last updated on: 2026-05-28
Assigner: Canonical Ltd.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ubuntu | linux | 6.8 |
| ubuntu | linux | 7.0 |
| ubuntu | linux | 7.17 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-457 | The code uses a variable that has not been initialized, leading to unpredictable or unintended results. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in Ubuntu Linux versions 6.8, 7.17, and 7.0, specifically in the AppArmor SAUCE patches. Under certain conditions, an unprivileged local user can trigger a bug caused by the use of an uninitialized variable in the notification handling code. This can lead to incorrect caching of AppArmor notification responses.
How can this vulnerability impact me? :
The vulnerability allows an unprivileged local user to cause incorrect caching of AppArmor notification responses. While it does not directly impact confidentiality or availability, it can affect the integrity of the notification handling process within AppArmor, potentially leading to misleading or incorrect security notifications.