CVE-2026-23404
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/04/2026
Last modified:
01/04/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
apparmor: replace recursive profile removal with iterative approach<br />
<br />
The profile removal code uses recursion when removing nested profiles,<br />
which can lead to kernel stack exhaustion and system crashes.<br />
<br />
Reproducer:<br />
$ pf=&#39;a&#39;; for ((i=0; i /sys/kernel/security/apparmor/.remove<br />
<br />
Replace the recursive __aa_profile_list_release() approach with an<br />
iterative approach in __remove_profile(). The function repeatedly<br />
finds and removes leaf profiles until the entire subtree is removed,<br />
maintaining the same removal semantic without recursion.
Impact
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/33959a491e9fd557abfa5fce5ae4637d400915d3
- https://git.kernel.org/stable/c/7eade846e013cbe8d2dc4a484463aa19e6515c7f
- https://git.kernel.org/stable/c/999bd704b0b641527a5ed46f0d969deff8cfa68b
- https://git.kernel.org/stable/c/a6a941a1294ac5abe22053dc501d25aed96e48fe
- https://git.kernel.org/stable/c/ab09264660f9de5d05d1ef4e225aa447c63a8747



