CVE-2026-23269

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/03/2026
Last modified:
02/04/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> apparmor: validate DFA start states are in bounds in unpack_pdb<br /> <br /> Start states are read from untrusted data and used as indexes into the<br /> DFA state tables. The aa_dfa_next() function call in unpack_pdb() will<br /> access dfa-&gt;tables[YYTD_ID_BASE][start], and if the start state exceeds<br /> the number of states in the DFA, this results in an out-of-bound read.<br /> <br /> ==================================================================<br /> BUG: KASAN: slab-out-of-bounds in aa_dfa_next+0x2a1/0x360<br /> Read of size 4 at addr ffff88811956fb90 by task su/1097<br /> ...<br /> <br /> Reject policies with out-of-bounds start states during unpacking<br /> to prevent the issue.