« Volver al listado

CVE-2026-93245

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

apparmor: policy_int make sure list heads are initialized before fail path

If profile create fails before policy_init is complete the list heads are not properly initialized causing profile_free() sanity checks to trigger the following splat.

Detalles técnicos trazas, registros y código del informe original
AppArmor WARN aa_policy_destroy: (((!list_empty(&policy->profiles) && (&policy->profiles)->prev != ((void *) 0x122 + (0xdead000000000000UL))))):
WARNING: security/apparmor/lib.c:509 at aa_policy_destroy+0x164/0x1b0 security/apparmor/lib.c:509, CPU#0: syz.0.17/5541
Modules linked in:
CPU: 0 UID: 0 PID: 5541 Comm: syz.0.17 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:aa_policy_destroy+0x16b/0x1b0 security/apparmor/lib.c:509
Code: 85 ed 7e 4d e8 96 bc 37 fd 5b 41 5c 41 5e 41 5f 5d e9 19 27 4e 07 cc e8 83 bc 37 fd 48 8d 3d 0c f0 d3 0b 48 c7 c6 a4 eb 38 8e <67> 48 0f b9 3a e9 04 ff ff ff e8 66 bc 37 fd 48 8d 3d ff ef d3 0b
RSP: 0018:ffffc9000345eaa0 EFLAGS: 00010293
RAX: ffffffff848f530d RBX: ffff88803f734800 RCX: ffff88801af2a580
RDX: 0000000000000000 RSI: ffffffff8e38eba4 RDI: ffffffff90634320
RBP: 0000000000000000 R08: 0000000000000cc0 R09: 00000000ffffffff
R10: dffffc0000000000 R11: fffffbfff1d95913 R12: dead000000000122
R13: ffff88803f734800 R14: ffff88803f734828 R15: dffffc0000000000
FS:  00007f5f6a1836c0(0000) GS:ffff88808c519000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 000055d02407b048 CR3: 0000000012aa9000 CR4: 0000000000352ef0
Call Trace:
 <TASK>
 aa_free_profile+0x9d/0x9f0 security/apparmor/policy.c:334
 aa_alloc_profile+0x1e4/0x3e0 security/apparmor/policy.c:416
 unpack_profile security/apparmor/policy_unpack.c:1153 [inline]
 aa_unpack+0x17db/0x7430 security/apparmor/policy_unpack.c:1748
 aa_replace_profiles+0x226/0x2a20 security/apparmor/policy.c:1183
 policy_update+0x234/0x4a0 security/apparmor/apparmorfs.c:505
 profile_load+0x1cb/0x320 security/apparmor/apparmorfs.c:522
 vfs_write+0x296/0xba0 fs/read_write.c:685
 ksys_write+0x150/0x270 fs/read_write.c:739
 do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline]
 do_syscall_64+0x166/0x520 arch/x86/entry/syscall_64.c:84
 entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f5f6939e0d9
Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007f5f6a183028 EFLAGS: 00000246 ORIG_RAX: 0000000000000001
RAX: ffffffffffffffda RBX: 00007f5f69625fa0 RCX: 00007f5f6939e0d9
RDX: 0000000000000041 RSI: 0000200000000400 RDI: 0000000000000003
RBP: 00007f5f6a183090 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001
R13: 00007f5f69626038 R14: 00007f5f69625fa0 R15: 00007ffe23725c18

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93245",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "fe6bb31f590c9cd9c8d3ddbdfd4301f72db91718",
              "lessThan": "88ba930e7d0586ca2700757249f1e6fc0bbab0fc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fe6bb31f590c9cd9c8d3ddbdfd4301f72db91718",
              "lessThan": "ee017ef9aa2cf20d85d4a20c09ef3db9fb240310",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fe6bb31f590c9cd9c8d3ddbdfd4301f72db91718",
              "lessThan": "62f159fac76468dbbfd977f4f18472d4a01e8d74",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fe6bb31f590c9cd9c8d3ddbdfd4301f72db91718",
              "lessThan": "0664c75afe87a1d7d4f4e1d7eecf50ad829fb6e8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fe6bb31f590c9cd9c8d3ddbdfd4301f72db91718",
              "lessThan": "4a09a5e6512a3792c78ae8e3ca79cb55a11eed57",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fe6bb31f590c9cd9c8d3ddbdfd4301f72db91718",
              "lessThan": "5449f715f24e86648f8cc8fba8d97ff6b5d04981",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fe6bb31f590c9cd9c8d3ddbdfd4301f72db91718",
              "lessThan": "dd52ab1c5436be86f5b8ca118fa8e5d61d63ffed",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fe6bb31f590c9cd9c8d3ddbdfd4301f72db91718",
              "lessThan": "3daad923a8685adb66087e0d819559b7eb6ba975",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "security/apparmor/lib.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.11"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.11",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.270",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "security/apparmor/lib.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-24T16:17:20.473",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0664c75afe87a1d7d4f4e1d7eecf50ad829fb6e8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3daad923a8685adb66087e0d819559b7eb6ba975",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4a09a5e6512a3792c78ae8e3ca79cb55a11eed57",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5449f715f24e86648f8cc8fba8d97ff6b5d04981",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/62f159fac76468dbbfd977f4f18472d4a01e8d74",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/88ba930e7d0586ca2700757249f1e6fc0bbab0fc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/dd52ab1c5436be86f5b8ca118fa8e5d61d63ffed",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ee017ef9aa2cf20d85d4a20c09ef3db9fb240310",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: policy_int make sure list heads are initialized before fail path\n\nIf profile create fails before policy_init is complete the list heads\nare not properly initialized causing profile_free() sanity checks to\ntrigger the following splat.\n\nAppArmor WARN aa_policy_destroy: (((!list_empty(&policy->profiles) && (&policy->profiles)->prev != ((void *) 0x122 + (0xdead000000000000UL))))):\nWARNING: security/apparmor/lib.c:509 at aa_policy_destroy+0x164/0x1b0 security/apparmor/lib.c:509, CPU#0: syz.0.17/5541\nModules linked in:\nCPU: 0 UID: 0 PID: 5541 Comm: syz.0.17 Not tainted syzkaller #0 PREEMPT(full)\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\nRIP: 0010:aa_policy_destroy+0x16b/0x1b0 security/apparmor/lib.c:509\nCode: 85 ed 7e 4d e8 96 bc 37 fd 5b 41 5c 41 5e 41 5f 5d e9 19 27 4e 07 cc e8 83 bc 37 fd 48 8d 3d 0c f0 d3 0b 48 c7 c6 a4 eb 38 8e <67> 48 0f b9 3a e9 04 ff ff ff e8 66 bc 37 fd 48 8d 3d ff ef d3 0b\nRSP: 0018:ffffc9000345eaa0 EFLAGS: 00010293\nRAX: ffffffff848f530d RBX: ffff88803f734800 RCX: ffff88801af2a580\nRDX: 0000000000000000 RSI: ffffffff8e38eba4 RDI: ffffffff90634320\nRBP: 0000000000000000 R08: 0000000000000cc0 R09: 00000000ffffffff\nR10: dffffc0000000000 R11: fffffbfff1d95913 R12: dead000000000122\nR13: ffff88803f734800 R14: ffff88803f734828 R15: dffffc0000000000\nFS:  00007f5f6a1836c0(0000) GS:ffff88808c519000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 000055d02407b048 CR3: 0000000012aa9000 CR4: 0000000000352ef0\nCall Trace:\n <TASK>\n aa_free_profile+0x9d/0x9f0 security/apparmor/policy.c:334\n aa_alloc_profile+0x1e4/0x3e0 security/apparmor/policy.c:416\n unpack_profile security/apparmor/policy_unpack.c:1153 [inline]\n aa_unpack+0x17db/0x7430 security/apparmor/policy_unpack.c:1748\n aa_replace_profiles+0x226/0x2a20 security/apparmor/policy.c:1183\n policy_update+0x234/0x4a0 security/apparmor/apparmorfs.c:505\n profile_load+0x1cb/0x320 security/apparmor/apparmorfs.c:522\n vfs_write+0x296/0xba0 fs/read_write.c:685\n ksys_write+0x150/0x270 fs/read_write.c:739\n do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline]\n do_syscall_64+0x166/0x520 arch/x86/entry/syscall_64.c:84\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7f5f6939e0d9\nCode: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007f5f6a183028 EFLAGS: 00000246 ORIG_RAX: 0000000000000001\nRAX: ffffffffffffffda RBX: 00007f5f69625fa0 RCX: 00007f5f6939e0d9\nRDX: 0000000000000041 RSI: 0000200000000400 RDI: 0000000000000003\nRBP: 00007f5f6a183090 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001\nR13: 00007f5f69626038 R14: 00007f5f69625fa0 R15: 00007ffe23725c18"
    }
  ],
  "lastModified": "2026-09-24T16:17:20.473",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}