Description
In the Linux kernel, the following vulnerability has been resolved:

apparmor: fix unconfined user namespace restriction forced stack

If a task is already confined by a stack the unprivileged transition
restriction on unconfined is not correctly, applied. This results in
an escape if two transitions through an unconfined profile can be
executed.

Fix this by pushing the check into the per profile label build. The
check will always be done against unconfined and result in a stack of
just the unconfined component when necessary.
Published: 2026-09-17
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Escaping AppArmor confinement via unconfined stack
Action: Patch Immediately
AI Analysis

Impact

In the Linux kernel's AppArmor security module, an incorrect check allows a task that is already confined by a stack to improperly grant privileged transitions when moving through an unconfined profile in a user namespace. This flaw permits an escape from the confinement stack, enabling a process to gain higher privileges than intended. The weakness involves improper access control enforcement, undermining the isolation enforced by AppArmor and potentially allowing an attacker to execute arbitrary code with elevated privileges within the affected system.

Affected Systems

The affected products are all Linux kernel implementations that include the AppArmor module, as identified by the Linux:Linux vendor descriptor. No specific kernel release numbers are listed, so all versions of the Linux kernel that contain AppArmor remain vulnerable until an update that incorporates the patch is applied.

Risk and Exploitability

The CVSS score of 8.4 classifies this vulnerability as a high severity issue, while the EPSS score of less than 1% indicates a low probability of being actively exploited in the near term. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector requires the ability to execute the unconfined user namespace transition twice, implying a local or privilege-domained environment. If exploited, the attacker can escape the AppArmor confinement stack, effectively gaining privileged execution rights within the kernel space. The combination of high severity and low exploitation probability suggests that while the issue is critical, active attacks are currently unlikely, but the risk of impact remains if the flaw is discovered and exploited by an advanced adversary.

Generated by OpenCVE AI on September 20, 2026 at 02:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel release that contains the AppArmor unconfined namespace stack check fix
  • Reboot the system into the updated kernel to activate the patch
  • Review and tighten AppArmor policies to restrict unconfined user namespace transitions if they are not required

Generated by OpenCVE AI on September 20, 2026 at 02:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 19 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: apparmor: fix unconfined user namespace restriction forced stack If a task is already confined by a stack the unprivileged transition restriction on unconfined is not correctly, applied. This results in an escape if two transitions through an unconfined profile can be executed. Fix this by pushing the check into the per profile label build. The check will always be done against unconfined and result in a stack of just the unconfined component when necessary.
Title apparmor: fix unconfined user namespace restriction forced stack
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:53:59.067Z

Reserved: 2026-09-11T19:38:34.794Z

Link: CVE-2026-90231

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:18.930

Modified: 2026-09-18T18:17:48.137

Link: CVE-2026-90231

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:45:18Z

Weaknesses