Impact
A use‑after‑free vulnerability exists in the AppArmor LSM hook of the Linux kernel. When the credential label of a running task is replaced during a security check, the kernel may drop references to the old credential structure while the task still holds a pointer to it. Accessing the freed structure can trigger a kernel crash or allow the execution of arbitrary code. This potential for privilege escalation is inferred because the UAF could enable kernel‑level code execution. For a local attacker this could lead to privilege escalation to kernel level.
Affected Systems
The flaw is present in the generic Linux kernel when AppArmor is compiled in, before the patched implementation of begin_current_label_crit_section() and related label‑replacement logic. All versions lacking the provided patch are vulnerable; no specific version range is listed.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score is less than 1%, reflecting a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, so no publicly known exploit exists at the time of this analysis. Attackers would need local access and the ability to trigger AppArmor label replacements; this requirement is inferred from the fact that the vulnerability involves credential manipulation within the kernel context. The likely attack vector is local, through a process that triggers credential replacement. If an exploit were crafted, it could result in privilege escalation.
OpenCVE Enrichment
Debian DSA