Out-of-Bounds Write Vulnerability in Linux Kernel's AppArmor by Linux Foundation
CVE-2026-89761

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-89761?

A critical out-of-bounds write vulnerability exists within the Linux kernel's AppArmor module, wherein the null termination of a label vector is inadequately handled. This flaw arises when invoking the aa_vec_unique function with a specific flag, allowing an unprivileged task to exploit system attributes accessible through the proc filesystem. The insufficient buffer allocation can lead to writing data beyond allocated memory, effectively creating a vector overflow. This vulnerability highlights the necessity for robust memory management and security checks in kernel processes.

Affected Version(s)

Linux f1bd904175e8190ce14aedee37e207ab51fe3b30 < 9124e078ea2250d8d01d2162a550acb01ef5bf48

Linux f1bd904175e8190ce14aedee37e207ab51fe3b30 < 28069434aef66b9d084f0609b7a29c171846815e

Linux f1bd904175e8190ce14aedee37e207ab51fe3b30 < 36bdd0b45ec3f4822832a56e9db8674c8450dfce

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.