Impact
The bug occurs in the Linux kernel’s AppArmor subsystem when the function unpack_pdb attempts to allocate an ACCEPT2 table for older policy files. If that allocation fails, an error message is set but the function mistakenly continues along the success path and returns a policy database lacking the required table. This incorrect error handling can cause AppArmor to operate with missing data, potentially leading to authorization gaps or failures to enforce security constraints. The issue is rooted in failure to detect and propagate error conditions.
Affected Systems
The vulnerability affects all Linux kernel installations that include the AppArmor component prior to the removal of this bug. Vendor data lists the product as Linux:Linux with no specific version range provided, meaning any kernel build that contains the affected code and has not been updated by a vendor patch is susceptible. Users of distributions that rely on the upstream kernel or apply the upstream patch without modification are also at risk.
Risk and Exploitability
Explicit exploitation information is absent from the CVE data; the EPSS score is <1%, indicating a very low exploitation probability, and the issue is not listed in the CISA KEV catalog. The flaw involves an internal kernel error path that could lead to a missing policy table if an ACCEPT2 allocation fails. It is not clear from the available information how an attacker could trigger this failure. If it could be triggered, the attack would likely require local or privileged kernel access. The CVSS score of 5.5 indicates moderate severity, but the bug could potentially lead to denial of service scenarios or weakened security controls within the affected system.
OpenCVE Enrichment