Bug 2448752 (CVE-2026-23268)
| Summary: | CVE-2026-23268 kernel: AppArmor: Local privilege escalation and denial of service via confused deputy attack | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | rhel-process-autobot, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in the Linux kernel's AppArmor component. An unprivileged local user can exploit a confused deputy attack by manipulating a privileged process to write to AppArmor interfaces. This allows the user to load, replace, and remove security profiles, leading to full policy management. The consequences include bypassing user namespace restrictions, removing confinement, causing a Denial of Service (DoS) by denying application execution, and potentially exploiting other kernel bugs for local privilege escalation.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-03-18 19:03:19 UTC
|