Impact
The vulnerability occurs in the Linux kernel AppArmor subsystem where invoking the change_hat function while AppArmor is in complain mode and the requested hat does not exist can lead to a deadlock; the deadlock is caused by change_hat acquiring a lock to search the hat list, then attempting to create a new learning profile that also needs the same lock, resulting in the calling task hanging indefinitely, and once a process is stuck the AppArmor subsystem becomes unresponsive to subsequent hat changes, effectively rendering the affected process and any further hat manipulations permanently blocked.
Affected Systems
Affected systems are Linux kernel images that implement AppArmor. The flaw was discovered in Ubuntu 26.04 LTS kernel 7.0.0, appears in the 7.2-rc7 release, and is also present in vanilla kernel 6.18.44. Debian’s 6.12.95 kernel, patched with Debian’s security updates, is not affected. Users running AppArmor in complain mode on any of these kernels are at risk.
Risk and Exploitability
The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating no known public exploits. The flaw can be triggered by submitting a change_hat request while AppArmor is in complain mode and the specified hat does not exist. The CVE description does not disclose the privilege level required to issue change_hat, so the escalation potential remains unspecified. While exploitation probability is low, a single unkillable process can cause a denial of service by freezing the AppArmor subsystem and impacting system stability and availability.
OpenCVE Enrichment