Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the AppArmor DFA policy engine.
Metrics
Affected Vendors & Products
References
History
Thu, 28 May 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canonical
Canonical ubuntu Linux |
|
| Vendors & Products |
Canonical
Canonical ubuntu Linux |
Thu, 28 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 May 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in invalid data being processed by the AppArmor DFA policy engine. | |
| Title | Out-of-bounds read in Ubuntu Linux AppArmor notification handling | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: canonical
Published: 2026-05-28T18:28:28.221Z
Updated: 2026-05-29T03:55:52.758Z
Reserved: 2026-05-19T10:37:36.433Z
Link: CVE-2026-47333
Updated: 2026-05-28T19:23:59.983Z
Status : Awaiting Analysis
Published: 2026-05-28T19:16:42.073
Modified: 2026-05-29T02:45:36.283
Link: CVE-2026-47333
No data.