Description
In the Linux kernel, the following vulnerability has been resolved:

apparmor: check label build before no_new_privs test

aa_change_profile() builds a replacement label with
fn_label_build_in_scope() before the no_new_privs subset check. The build
helper can fail and return NULL or an ERR_PTR, but the result was passed
to aa_label_is_unconfined_subset() before the existing IS_ERR_OR_NULL()
check.

Reuse the existing target-label build failure handling immediately after
the build. This preserves the current audit handling while preventing the
subset helper from dereferencing an invalid label.
Published: 2026-08-15
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In the Linux kernel's AppArmor subsystem, a flaw in aa_change_profile allows an invalid label reference to be supplied to aa_label_is_unconfined_subset when a prior label build fails. The code path does not verify that the result is NULL or an error pointer before dereferencing it, leading to a kernel panic. The impact is purely a denial of service, as the system crashes without granting code execution or privilege escalation.

Affected Systems

The vulnerability exists in all Linux kernel builds that include the AppArmor profile management module. Because no specific kernel version range is listed, the flaw may exist across a broad spectrum of kernel releases until an update that contains the patch is applied.

Risk and Exploitability

There is no EPSS or CVSS score provided, but the severity of a kernel panic is high. The flaw requires an attacker to trigger aa_change_profile with an invalid label build, a scenario most likely achievable with local privileges or by manipulating AppArmor profiles. It is not currently listed in the CISA KEV catalog, so active exploitation in the wild has not been documented. Nevertheless, the potential for system-wide downtime makes it a critical issue that should be addressed as soon as possible.

Generated by OpenCVE AI on August 15, 2026 at 11:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that contains the CVE‑2026‑72460 fix.
  • If an upgrade cannot be performed immediately, temporarily disable or remove AppArmor from the system until the patch is applied.
  • Monitor system logs for kernel panics and verify that any scripts or applications that invoke aa_change_profile are properly validated to avoid forced failures.

Generated by OpenCVE AI on August 15, 2026 at 11:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 15 Aug 2026 12:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: apparmor: check label build before no_new_privs test aa_change_profile() builds a replacement label with fn_label_build_in_scope() before the no_new_privs subset check. The build helper can fail and return NULL or an ERR_PTR, but the result was passed to aa_label_is_unconfined_subset() before the existing IS_ERR_OR_NULL() check. Reuse the existing target-label build failure handling immediately after the build. This preserves the current audit handling while preventing the subset helper from dereferencing an invalid label.
Title apparmor: check label build before no_new_privs test
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-15T05:57:05.404Z

Reserved: 2026-08-09T03:40:39.932Z

Link: CVE-2026-72460

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:19.993

Modified: 2026-08-15T06:22:19.993

Link: CVE-2026-72460

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-15T11:45:03Z

Weaknesses