Impact
An integer overflow in AppArmor’s verify_tags function allows an attacker to supply a crafted policy that causes the function to read past the bounds of the tagset table. The overflow bypasses the bounds check, leading to an out-of-bounds read during policy load. This read can expose kernel memory contents and potentially enable privilege escalation or confidential data disclosure.
Affected Systems
Linux kernel; affected products are Linux:Linux, but the specific kernel releases impacted are not listed in the CVE data. Administering the fix requires applying the kernel patch that addresses the overflow in verify_tags.
Risk and Exploitability
The vulnerability has a CVSS score of 7.1 and an EPSS score of less than 1%, indicating low to moderate exploitation probability. It is not listed in the CISA KEV catalog. The flaw can be exploited by an unprivileged process inside a nested user namespace with the sysctl unprivileged_userns_apparmor_policy set to 1, which allows loading of custom AppArmor profiles. The attack path involves supplying a malicious policy blob that triggers the overflow during verify_tags, leading to the out-of-bounds read.
OpenCVE Enrichment