CVE-2026-47332: Canonical Ubuntu Linux
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly validate the size of an internal structure, leading to an out-of-bounds read in notification handling code. The bug can be triggered by an unprivileged local user and can result in information disclosure from adjacent slab objects.
Affected products
- Canonical Ubuntu Linux: version 24.04 only; version 25.10 only; version 26.04 only
Published 2026-05-28. Last modified 2026-06-17.