CVE-2026-23403: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix memory leak in verify_header The function sets `*ns = NULL` on every call, leaking the namespace string allocated in previous iterations when multiple profiles are unpacked. This also breaks namespace consistency checking since *ns is always NULL when the comparison is made. Remove the incorrect assignment. The caller (aa_unpack) initializes *ns to NULL once before the loop, which is sufficient.
Affected products
- Linux Linux Kernel: from 3.12.1, before 5.10.253 (fixed in 5.10.253); from 5.11, before 5.15.203 (fixed in 5.15.203); from 5.16, before 6.1.169 (fixed in 6.1.169); from 6.2, before 6.6.130 (fixed in 6.6.130); from 6.7, before 6.12.77 (fixed in 6.12.77); from 6.13, before 6.18.18 (fixed in 6.18.18); …
Published 2026-04-01. Last modified 2026-06-17.