CVE-2026-23408

medium Red Hat
EPSS Score
0.0%
Exploitation probability in 30 days
Top 95% most likely to be exploited
Published: April 1, 2026 (43 days ago)
Last Modified: April 1, 2026
Vendor: Red Hat
Source: REDHAT

Description

A flaw was found in AppArmor within the Linux kernel. This vulnerability involves a double free of the `ns_name` variable in the `aa_replace_profiles()` function. This can occur when `ns_name` is assigned from `ent->ns_name` without properly nulling out `ent->ns_name`, leading to it being freed twice. A local attacker could potentially exploit this memory corruption to cause a denial of service or other unpredictable system behavior.

CWE

CWE-1341

Affected Products

Red Hat Enterprise Linux 10Red Hat Enterprise Linux 6Red Hat Enterprise Linux 7Red Hat Enterprise Linux 8Red Hat Enterprise Linux 9

References