Description
In the Linux kernel, the following vulnerability has been resolved:

apparmor: fail policy unpack on accept2 allocation failure

unpack_pdb() may need to allocate a missing ACCEPT2 table for older policy
data. If that allocation failed, it set an error message but jumped to the
success path, returning a policydb with the required table missing.

Return -ENOMEM through the normal failure path when the ACCEPT2 allocation
fails. Remove the now-unused out label.
Published: 2026-08-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The bug occurs in the Linux kernel’s AppArmor subsystem when the function unpack_pdb attempts to allocate an ACCEPT2 table for older policy files. If that allocation fails, an error message is set but the function mistakenly continues along the success path and returns a policy database lacking the required table. This incorrect error handling can cause AppArmor to operate with missing data, potentially leading to authorization gaps or failures to enforce security constraints. The issue is rooted in failure to detect and propagate error conditions.

Affected Systems

The vulnerability affects all Linux kernel installations that include the AppArmor component prior to the removal of this bug. Vendor data lists the product as Linux:Linux with no specific version range provided, meaning any kernel build that contains the affected code and has not been updated by a vendor patch is susceptible. Users of distributions that rely on the upstream kernel or apply the upstream patch without modification are also at risk.

Risk and Exploitability

Explicit exploitation information is absent from the CVE data; the EPSS score is <1%, indicating a very low exploitation probability, and the issue is not listed in the CISA KEV catalog. The flaw involves an internal kernel error path that could lead to a missing policy table if an ACCEPT2 allocation fails. It is not clear from the available information how an attacker could trigger this failure. If it could be triggered, the attack would likely require local or privileged kernel access. The CVSS score of 5.5 indicates moderate severity, but the bug could potentially lead to denial of service scenarios or weakened security controls within the affected system.

Generated by OpenCVE AI on August 22, 2026 at 06:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the kernel patch that fixes the allocation failure in unpack_pdb
  • Restart the system to load the updated kernel
  • Monitor kernel logs for any AppArmor‑related warnings or denials

Generated by OpenCVE AI on August 22, 2026 at 06:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-390

Wed, 19 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-252
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Sat, 15 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-390

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: apparmor: fail policy unpack on accept2 allocation failure unpack_pdb() may need to allocate a missing ACCEPT2 table for older policy data. If that allocation failed, it set an error message but jumped to the success path, returning a policydb with the required table missing. Return -ENOMEM through the normal failure path when the ACCEPT2 allocation fails. Remove the now-unused out label.
Title apparmor: fail policy unpack on accept2 allocation failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:15:01.418Z

Reserved: 2026-08-09T03:40:39.932Z

Link: CVE-2026-72457

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:19.690

Modified: 2026-08-17T06:19:13.360

Link: CVE-2026-72457

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72457 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T06:45:04Z

Weaknesses