CVE-2026-23410
Last modified
CVE-2026-23410 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race on rawdata dereference There is a race condition that leads to a use-after-free situation: because the rawdata inodes are not refcounted, an attacker can start open()ing one of the rawdata files, and at the same time remove the last reference to this rawdata (by removing the corresponding profile, for example), which frees its struct aa_loaddata; as a result, when seq_rawdata_open() is reached, i_private is a dangling pointer and freed memory is accessed. The rawdata inodes weren't refcounted to avoid a circular refcount and were supposed to be held by the profile rawdata reference. However during profile removal there is a window where the vfs and profile destruction race, resulting in the use after free. Fix this by moving to a double refcount scheme. EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race on rawdata dereference There is a race condition that leads to a use-after-free situation: because the rawdata inodes are not refcounted, an attacker can start open()ing one of the rawdata files, and at the same time remove the last reference to this rawdata (by removing the corresponding profile, for example), which frees its struct aa_loaddata; as a result, when seq_rawdata_open() is reached, i_private is a dangling pointer and freed memory is accessed. The rawdata inodes weren't refcounted to avoid a circular refcount and were supposed to be held by the profile rawdata reference. However during profile removal there is a window where the vfs and profile destruction race, resulting in the use after free. Fix this by moving to a double refcount scheme. Where the profile refcount on rawdata is used to break the circular dependency. Allowing for freeing of the rawdata once all inode references to the rawdata are put.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Linux | Linux Kernel | >= 4.13.1, < 5.10.253 | — |
| Linux | Linux Kernel | >= 5.11, < 5.15.203 | — |
| Linux | Linux Kernel | >= 5.16, < 6.1.169 | — |
| Linux | Linux Kernel | >= 6.2, < 6.6.130 | — |
| Linux | Linux Kernel | >= 6.7, < 6.12.77 | — |
| Linux | Linux Kernel | >= 6.13, < 6.18.18 | — |
| Linux | Linux Kernel | >= 6.19, < 6.19.8 | — |
| Linux | Linux Kernel | 4.13 | — |
| Linux | Linux Kernel | 7.0 | Rc1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-23410?
How severe is CVE-2026-23410?
How do I fix CVE-2026-23410?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-23404In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2026-23405In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2026-23406In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-23407In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-23408In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-23409In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2026-23411In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-23412In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-23413In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-23414In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2026-23415In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-23416In the Linux kernel, the following vulnerability has been re…5.5
Are you affected by CVE-2026-23410?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
