Description
Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent slab objects.
Published: 2026-05-28
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds read occurs in AppArmor’s notification handling code in Ubuntu Linux kernels 6.8, 6.17 and 7.0. The bug arises from a faulty size check of an internal structure used during notification processing. The read can access data from adjacent slab objects, enabling a local user to exfiltrate sensitive information that normally resides only within protected memory regions. The weakness is classified under CWE‑125. The impact is limited to confidentiality of system memory content; there is no direct modification of system state, so integrity and availability are not directly affected.

Affected Systems

Canonical’s Ubuntu Linux product family is affected, specifically kernel versions 6.8, 6.17 and 7.0 used in the noble release series. No other vendors or product lines are listed, so the scope is confined to Ubuntu systems running these kernel releases.

Risk and Exploitability

The vulnerability can be exploited locally by any unprivileged user with access to the target host. The CVSS score of 5.5 places it in the medium severity range. Because the EPSS score is not available, exploitation probability cannot be quantified, and the issue is not listed in the CISA KEV catalog. An attacker would need to trigger the notification handling path, which may be a routine operation within AppArmor profile management. While the attack is limited to information disclosure, the lack of a widely deployed patch suggests that exploitation may occur in environments that have not yet applied security updates.

Generated by OpenCVE AI on May 28, 2026 at 21:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Ubuntu kernel update that includes the SAUCE patch for AppArmor notification handling
  • If immediate patching is not feasible, consider disabling AppArmor notifications by stopping the apparmor service or using a kernel config that removes the notification path
  • Restrict unprivileged users from triggering AppArmor notifications by tightening permissions on relevant kernel interfaces or reducing profile modification rights

Generated by OpenCVE AI on May 28, 2026 at 21:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8370-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8371-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8373-1 Linux kernel vulnerabilities
Ubuntu USN Ubuntu USN USN-8374-1 Linux kernel vulnerabilities
History

Tue, 09 Jun 2026 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:canonical:ubuntu_linux:24.04:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:25.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:26.04:*:*:*:*:*:*:*

Thu, 28 May 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Canonical
Canonical ubuntu Linux
Vendors & Products Canonical
Canonical ubuntu Linux

Thu, 28 May 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 28 May 2026 19:00:00 +0000

Type Values Removed Values Added
Description Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent slab objects.
Title Out-of-bounds read in Ubuntu Linux AppArmor notification handling
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Canonical Ubuntu Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: canonical

Published:

Updated: 2026-05-28T19:24:19.013Z

Reserved: 2026-05-19T10:37:36.433Z

Link: CVE-2026-47332

cve-icon Vulnrichment

Updated: 2026-05-28T19:24:14.522Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-28T19:16:41.960

Modified: 2026-06-09T14:40:31.463

Link: CVE-2026-47332

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-28T23:30:26Z

Weaknesses