Impact
This kernel vulnerability is an out-of-bounds write that occurs when AppArmor null terminates a label vector. An unprivileged user can trigger the flaw by writing to /proc/self/attr/apparmor/current or by calling lsm_set_self_attr, both of which do not enforce permission checks before parsing the label. The buffer overflow may corrupt adjacent memory, creating a path for an attacker to execute arbitrary code or gain elevated privileges.
Affected Systems
This issue affects all Linux kernel builds that include AppArmor, regardless of distribution or kernel version. The flaw resides in the AppArmor label parsing logic and is present whenever label vectors are processed by aa_vec_unique or aa_label_strn_parse.
Risk and Exploitability
The CVSS score of 7.8 indicates moderate to high severity, and the EPSS score remains very low (<1%), suggesting a modest exploitation probability; the vulnerability is not listed in the CISA KEV catalog. The attack vector is local, as an unprivileged process can write to /proc/self/attr/apparmor/current or invoke the LSM syscall before permission checks are performed. Successful exploitation would enable arbitrary writes that could be leveraged to execute code or elevate privileges on the affected host.
OpenCVE Enrichment
Debian DSA