#VU124773 Resource exhaustion in Linux kernel - CVE-2026-23405
Published: April 1, 2026
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper resource management in the AppArmor policy namespace subsystem when creating nested policy namespaces. A local user can create deeply nested policy namespaces to cause a denial of service.
Exploitation requires the ability to create AppArmor policy namespaces, which is available to unprivileged users in a user namespace.
Remediation
External links
- https://git.kernel.org/stable/c/306039414932c80f8420695a24d4fe10c84ccfb2
- https://git.kernel.org/stable/c/3f8699b3ee0c04b4b9bc27b82cd89a40e81e1d2e
- https://git.kernel.org/stable/c/7b6495ead2c611647f6b11441a852324e3eb8616
- https://git.kernel.org/stable/c/853ce31ca72097d23991a06876a2ccb5cb64b603
- https://git.kernel.org/stable/c/d42b2b6bb77ca40ee34ab74ad79305840b5f315d