apparmor: fix rlimit for posix cpu timers
Summary
| CVE | CVE-2026-46328 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-06-09 14:16:42 UTC |
| Updated | 2026-06-14 06:16:25 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: apparmor: fix rlimit for posix cpu timers Posix cpu timers requires an additional step beyond setting the rlimit. Refactor the code so its clear when what code is setting the limit and conditionally update the posix cpu timers when appropriate. |
Risk And Classification
Primary CVSS: v3.1 7.3 HIGH from 416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
EPSS: 0.000240000 probability, percentile 0.073120000 (date 2026-06-13)
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | Secondary | 7.3 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H |
| 3.1 | CNA | DECLARED | 7.3 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
ChangedConfidentiality
NoneIntegrity
LowAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected baa73d9e478ff32d62f3f9422822b59dd9a95a21 e1cc11550b2f66687a374536c9dfdddcefca0efe git | Not specified |
| CNA | Linux | Linux | affected baa73d9e478ff32d62f3f9422822b59dd9a95a21 2232d7cd243833ad750cae656d1817fe43744a09 git | Not specified |
| CNA | Linux | Linux | affected baa73d9e478ff32d62f3f9422822b59dd9a95a21 28aa93fcfb33b6d580c5df4ae8b6d13fb0e6fcd3 git | Not specified |
| CNA | Linux | Linux | affected baa73d9e478ff32d62f3f9422822b59dd9a95a21 1f736dfe27c857b78f8461cd7c3dd9640be74b37 git | Not specified |
| CNA | Linux | Linux | affected baa73d9e478ff32d62f3f9422822b59dd9a95a21 e43818b16815c0c2bf933ef28316f8e704e5e0ef git | Not specified |
| CNA | Linux | Linux | affected baa73d9e478ff32d62f3f9422822b59dd9a95a21 9bf1fa150775b0c6b794e4b6a2c0395e13777999 git | Not specified |
| CNA | Linux | Linux | affected baa73d9e478ff32d62f3f9422822b59dd9a95a21 57d51d41b90eface809b72e0e009b50546492f1f git | Not specified |
| CNA | Linux | Linux | affected baa73d9e478ff32d62f3f9422822b59dd9a95a21 6ca56813f4a589f536adceb42882855d91fb1125 git | Not specified |
| CNA | Linux | Linux | affected 4.10 | Not specified |
| CNA | Linux | Linux | unaffected 4.10 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.252 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.202 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.165 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.128 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.75 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.14 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.19.4 6.19.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.0 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/2232d7cd243833ad750cae656d1817fe43744a09 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/9bf1fa150775b0c6b794e4b6a2c0395e13777999 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/1f736dfe27c857b78f8461cd7c3dd9640be74b37 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/e43818b16815c0c2bf933ef28316f8e704e5e0ef | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/e1cc11550b2f66687a374536c9dfdddcefca0efe | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/6ca56813f4a589f536adceb42882855d91fb1125 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/57d51d41b90eface809b72e0e009b50546492f1f | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/28aa93fcfb33b6d580c5df4ae8b6d13fb0e6fcd3 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.