CVE-2026-47328
Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly attempt to free a pointer which was not previously kmalloc()d, while at the same time leaking allocated memory. The bug can be triggered by an unprivileged local user and can result in the corruption of slab metadata and could lead to resource exhaustion.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.1
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
- EPSS probability
- 0.09%
- CWE
- CWE-590
- Published
- 2026-05-28
- Last modified
- 2026-05-28
Affected products
- Canonical Ubuntu Linux
- Canonical Ubuntu Linux
- Canonical Ubuntu Linux
Weakness type
Related vulnerabilities
- CVE-2026-89161 — In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a...
- CVE-2026-18582 — mz-automation libiec61850 Report Sending Path reporting.c Reporting_RCBWriteAccessHandler free of memory not on the heap
- CVE-2025-7006 — Avast antivirus use of stack memory after free when scanning a malformed PE file
- CVE-2026-20810 — Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
- CVE-2025-54899 — Microsoft Excel Remote Code Execution Vulnerability
- CVE-2025-42996 — Multiple vulnerabilities in SAP MDM Server
- CVE-2025-42995 — Multiple vulnerabilities in SAP MDM Server
- CVE-2025-42994 — Multiple vulnerabilities in SAP MDM Server