« Volver al listado

CVE-2026-47330

Estado: AnalizadaBaja (3.3)—

Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-47330",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-47330",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-28T19:19:48.305274Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@ubuntu.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.3,
          "attackVector": "LOCAL",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@ubuntu.com",
      "affectedData": [
        {
          "repo": "https://git.launchpad.net/~ubuntu-kernel/ubuntu/+source/linux/",
          "vendor": "Canonical",
          "modules": [
            "AppArmor"
          ],
          "product": "Ubuntu Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.8.0",
              "lessThan": "6.8.0-124.124",
              "versionType": "dpkg"
            },
            {
              "status": "affected",
              "version": "6.17.0",
              "lessThan": "6.17.0-35.35",
              "versionType": "dpkg"
            },
            {
              "status": "affected",
              "version": "7.0.0",
              "lessThan": "7.0.0-22.22",
              "versionType": "dpkg"
            }
          ],
          "packageName": "linux",
          "collectionURL": "https://launchpad.net/ubuntu/+source/",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-05-28T19:16:41.530",
  "references": [
    {
      "url": "https://git.launchpad.net/~ubuntu-kernel/ubuntu/+source/linux/+git/noble/commit/?id=9b2c6eded493fa50e7c8cd3618d7ebe1358abaab",
      "tags": [
        "Patch"
      ],
      "source": "security@ubuntu.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@ubuntu.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-457"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses."
    }
  ],
  "lastModified": "2026-06-17T10:54:31.253",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:canonical:ubuntu_linux:24.04:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "62D1BEC7-1A71-4991-A1A5-0E3D282100EC"
            },
            {
              "criteria": "cpe:2.3:o:canonical:ubuntu_linux:25.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "68D562DD-F22D-4310-93C7-7DE817104CAC"
            },
            {
              "criteria": "cpe:2.3:o:canonical:ubuntu_linux:26.04:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2BB2642A-AA54-4949-A9FC-0E9673539350"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@ubuntu.com"
}