Incorrect validation of field size in Ubuntu Linux AppArmor notification responses
Summary
| CVE | CVE-2026-47329 |
|---|---|
| State | PUBLISHED |
| Assigner | canonical |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-28 19:16:41 UTC |
| Updated | 2026-05-29 02:45:36 UTC |
| Description | Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor notification responses. The bug can be triggered by an unprivileged local user and could result in handling of crafted responses. |
Risk And Classification
Primary CVSS: v3.1 3.3 LOW from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Problem Types: CWE-1284 | CWE-1284 CWE-1284 Improper validation of specified quantity in input
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 3.3 | LOW | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
| 3.1 | CNA | CVSS | 3.3 | LOW | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
LowAvailability
NoneCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Canonical | Ubuntu Linux | affected 6.8.0 6.8.0-124.124 dpkg | Not specified |
| CNA | Canonical | Ubuntu Linux | affected 6.17.0 6.17.0-35.35 dpkg | Not specified |
| CNA | Canonical | Ubuntu Linux | affected 7.0.0 7.0.0-22.22 dpkg | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.launchpad.net/~ubuntu-kernel/ubuntu/+source/linux/+git/noble/commit | [email protected] | git.launchpad.net | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Tristan Madani (@TristanInSec), Talence Security (en)
There are currently no legacy QID mappings associated with this CVE.