CVE-2026-47331: Canonical Ubuntu Linux
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Ubuntu Linux 6.8 contains AppArmor SAUCE patches which fail to acquire a lock when modifying a linked list. An unprivileged local user could trigger the race condition that can lead to a use-after-free (UAF) and, theoretically, arbitrary code execution.
Affected products
- Canonical Ubuntu Linux: version 24.04 only; version 25.10 only; version 26.04 only
Published 2026-05-28. Last modified 2026-06-17.