Memory Vulnerability in Linux Kernel's AppArmor Functionality
CVE-2026-89762

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-89762?

A use-after-free vulnerability in the Linux kernel's AppArmor module could potentially allow an attacker to exploit a failure to properly check and replace credentials during security hook invocations. This flaw arises when the function begin_current_label_crit_section() inadvertently leads to accessing outdated credential structures. In scenarios where credentials are overridden, the incompatibility between objective and subjective credentials can result in corrupted memory references, leading to unstable system behavior. The issue is particularly critical given the frequent invocation of these hooks and their potential for causing significant disruptions in kernel operations.

Affected Version(s)

Linux c75afcd153f6147d3b094f45a1d87e5df7f4f053 < 361488984d668235438faac28635f3632351407f

Linux c75afcd153f6147d3b094f45a1d87e5df7f4f053 < 587a6a92b93ec314c583bbf747413af170d42540

Linux c75afcd153f6147d3b094f45a1d87e5df7f4f053 < 580f777d6d9fd07fc034bd1aeba5c30fd48871a2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.