CVE-2026-23405

Updated on 01 Apr 2026

Severity

5.5 Medium severity

Details

CVSS score
5.5
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Overview

About vulnerability

In the Linux kernel, the following vulnerability has been resolved:

apparmor: fix: limit the number of levels of policy namespaces

Currently the number of policy namespaces is not bounded relying on the user namespace limit. However policy namespaces aren’t strictly tied to user namespaces and it is possible to create them and nest them arbitrarily deep which can be used to exhaust system resource.

Hard cap policy namespaces to the same depth as user namespaces.

Details

Fixes

KernelCare state

Live-patch status from KernelCare for each operating system.

Operating system Status Covered kernels
Debian 13 Ready For Release
Ubuntu 16.04 AWS HWE ESM Planned
Ubuntu 16.04 GCP ESM Planned
Ubuntu 16.04 HWE ESM Planned
Ubuntu 18.04 Planned
Ubuntu 18.04 AWS Planned
Ubuntu 18.04 Azure Planned
Ubuntu 18.04 GCP Planned