In the Linux kernel, the following vulnerability has been resolved:
apparmor: fix: limit the number of levels of policy namespaces
Currently the number of policy namespaces is not bounded relying on
the user namespace limit. However policy namespaces aren't strictly
tied to user namespaces and it is possible to create them and nest
them arbitrarily deep which can be used to exhaust system resource.
Hard cap policy namespaces to the same depth as user namespaces.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-04-01 09:16
Updated : 2026-06-17 10:21
NVD link : CVE-2026-23405
Mitre link : CVE-2026-23405
CVE.ORG link : CVE-2026-23405
JSON object : View
Products Affected
linux
- linux_kernel
CWE
