In the Linux kernel, the following vulnerability has been resolved:
apparmor: fix race between freeing data and fs accessing it
AppArmor was putting the reference to i_private data on its end after removing the original entry from the file system. However the inode can aand does live beyond that point and it is possible that some of the fs call back functions will be invoked after the reference has been put, which results in a race between freeing the data and accessing it through the fs.
While the rawdata/loaddata is the most likely candidate to fail the race, as it has the fewest references. If properly crafted it might be possible to trigger a race for the other types stored in i_private.
Fix this by moving the put of i_private referenced data to the correct place which is during inode eviction.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Apr 2, 2026 | Apr 2, 2026 |
| Ubuntu | — | Upgrade linux-image-azureUpgrade linux-image-azure-fips-6.8Upgrade linux-image-aws-fipsUpgrade linux-image-4.15.0-1184-gcpUpgrade linux-image-virtual-hwe-16.04Upgrade linux-image-4.15.0-1153-oracleUpgrade linux-image-5.15.0-1109-azure-fipsUpgrade linux-image-raspiUpgrade linux-image-azure-lts-18.04Upgrade linux-image-4.15.0-2092-gcp-fipsUpgrade linux-image-bluefield-5.4Upgrade linux-image-5.15.0-1109-azureUpgrade linux-image-5.4.0-1161-azureUpgrade linux-image-azure-lts-22.04Upgrade linux-image-fipsUpgrade linux-image-gcp-fips-4.15Upgrade linux-image-6.8.0-1052-azure-fipsUpgrade linux-image-6.17.0-1017-oemUpgrade linux-image-oem-24.04aUpgrade linux-image-gcp-fipsUpgrade linux-image-xilinx-6.8Upgrade linux-image-5.15.0-1096-intel-iot-realtimeUpgrade linux-image-genericUpgrade linux-image-intel-iot-realtime-5.15Upgrade linux-image-4.15.0-1146-fipsUpgrade linux-image-raspi2Upgrade linux-image-aws-hweUpgrade linux-image-intel-iot-realtimeUpgrade linux-image-4.15.0-1191-awsUpgrade linux-image-aws-4.15Upgrade linux-image-lowlatencyUpgrade linux-image-4.15.0-2129-aws-fipsUpgrade linux-image-azure-fipsUpgrade linux-image-gcp-4.15Upgrade linux-image-azure-cvmUpgrade linux-image-oem-24.04bUpgrade linux-image-5.4.0-1116-bluefieldUpgrade linux-image-oem-24.04cUpgrade linux-image-4.15.0-2109-azure-fipsUpgrade linux-image-oracle-4.15Upgrade linux-image-oracleUpgrade linux-image-bluefieldUpgrade linux-image-gcpUpgrade linux-image-4.15.0-1200-azureUpgrade linux-image-xilinx-zynqmpUpgrade linux-image-aws-fips-4.15Upgrade linux-image-5.15.0-1110-azureUpgrade linux-image-azure-fips-5.15Upgrade linux-image-generic-hwe-16.04Upgrade linux-image-azure-5.15Upgrade linux-image-lowlatency-hwe-16.04Upgrade linux-image-raspi-hwe-18.04Upgrade linux-image-oemUpgrade linux-image-azure-fips-4.15Upgrade linux-image-aws-lts-18.04Upgrade linux-image-4.15.0-249-lowlatencyUpgrade linux-image-4.15.0-249-genericUpgrade linux-image-xilinxUpgrade linux-image-gcp-lts-18.04Upgrade linux-image-kvmUpgrade linux-image-oem-24.04Upgrade linux-image-gkeUpgrade linux-image-raspi-5.4Upgrade linux-image-oracle-lts-18.04Upgrade linux-image-oem-24.04dUpgrade linux-image-5.4.0-1139-raspiUpgrade linux-image-virtualUpgrade linux-image-oem-6.17Upgrade linux-image-6.8.0-1029-xilinxUpgrade linux-image-4.15.0-1173-kvmUpgrade linux-image-azure-5.4Upgrade linux-image-azure-4.15 | Apr 3, 2026 | Apr 1, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Apr 1, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub