{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89761","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.764Z","datePublished":"2026-09-11T19:47:02.837Z","dateUpdated":"2026-09-13T06:34:05.104Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:34:05.104Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: fix out-of-bounds write when null terminating a label vec\n\naa_vec_unique() null terminates at vec[n - dups] when VEC_FLAG_TERMINATE\nis passed. If the components are all distinct no duplicates are dropped,\ndups is 0 and the terminator goes to vec[n], so the caller has to provide\nroom for n + 1 entries.\n\naa_label_strn_parse() sets up its vector with vec_setup(profile, vec, len,\ngfp) and then calls aa_vec_unique(vec, len, VEC_FLAG_TERMINATE), but\nvec_setup() does not reserve the terminator entry. Up to LOCAL_VEC_ENTRIES\nit uses the local array of LOCAL_VEC_ENTRIES pointers, above that it\nallocates exactly len pointers. The terminator therefore lands one entry\npast the end of the local array when len is LOCAL_VEC_ENTRIES, and one\nentry past the end of the allocation when len is larger.\n\nlen comes from the number of \"//&\" separated components in the label name\nand label_count_strn_entries() does not bound it. An unprivileged task\nreaches the parse by writing to /proc/self/attr/apparmor/current or through\nlsm_set_self_attr(2), both of which go through do_setattr(), and the name\nis parsed before the change_profile permission is checked.\nThe query_label() path behind the securityfs .access file, which is\nmode 0666, performs no permission check at all. Every component has to\nresolve to a loaded profile, so a system with policy loaded is required.\n\nThe other two VEC_FLAG_TERMINATE users work on a label vec that\naa_label_alloc() has already sized with \"+ 1 for null terminator entry on\nvec\". Reserve the same entry in vec_setup() and DEFINE_VEC(). Passing\nlen + 1 from the caller instead would move len == LOCAL_VEC_ENTRIES out of\nthe local array and into kzalloc()."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - An unprivileged local process reaches aa_label_strn_parse() by writing a compound label to /sys/kernel/security/apparmor/.access (mode 0666) via query_label()/query_data(), or via /proc/self/attr/apparmor/current and lsm_set_self_attr(2) through do_setattr(); there is no network-facing path.\nAC:L - The attacker fully controls the \"//&\"-separated label string and thus the vector length; when at least eight distinct profiles are loaded (typical Ubuntu/Debian/SUSE policy, or attacker-loaded via user namespaces) with no duplicates, aa_vec_unique() deterministically writes NULL one pointer past the stack array or heap allocation, with no race.\nPR:L - query_label() on the world-writable .access file performs no capability or change_profile check, and do_setattr() parses the name before AA_MAY_CHANGE_PROFILE is tested, so a basic unprivileged local user suffices; real root is not required.\nUI:N - The attacker opens and writes the .access query or their own procattr themselves; no victim action such as mounting a filesystem or opening a file is required.\nS:U - The out-of-bounds write corrupts kernel stack or heap within the same kernel security authority. This is standard local privilege-escalation impact, not a VM escape or IOMMU/sandbox boundary crossing.\nC:H - The one-pointer out-of-bounds write lands in adjacent stack locals or the next kmalloc object. With attacker-chosen allocation size (component count) for heap grooming, that corruption can be leveraged as a kernel memory-disclosure primitive, so confidentiality impact is high.\nI:H - aa_vec_unique() writes a NULL pointer one slot past a LOCAL_VEC_ENTRIES stack array or a heap buffer sized exactly to the attacker-chosen component count. An out-of-bounds write that corrupts adjacent kernel objects is a write primitive suitable for control-flow hijacking.\nA:H - Corrupting an adjacent stack pointer, heap object, or stack canary can oops, panic, or hang the kernel; the unexploited NULL write alone is sufficient for denial of service."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["security/apparmor/include/label.h"],"versions":[{"version":"f1bd904175e8190ce14aedee37e207ab51fe3b30","lessThan":"9124e078ea2250d8d01d2162a550acb01ef5bf48","status":"affected","versionType":"git"},{"version":"f1bd904175e8190ce14aedee37e207ab51fe3b30","lessThan":"28069434aef66b9d084f0609b7a29c171846815e","status":"affected","versionType":"git"},{"version":"f1bd904175e8190ce14aedee37e207ab51fe3b30","lessThan":"36bdd0b45ec3f4822832a56e9db8674c8450dfce","status":"affected","versionType":"git"},{"version":"f1bd904175e8190ce14aedee37e207ab51fe3b30","lessThan":"9f1e40193eef7f047e6b77cfb4b4cafdecd7a123","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["security/apparmor/include/label.h"],"versions":[{"version":"4.13","status":"affected"},{"version":"0","lessThan":"4.13","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.13","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.13","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.13","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.13","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/9124e078ea2250d8d01d2162a550acb01ef5bf48"},{"url":"https://git.kernel.org/stable/c/28069434aef66b9d084f0609b7a29c171846815e"},{"url":"https://git.kernel.org/stable/c/36bdd0b45ec3f4822832a56e9db8674c8450dfce"},{"url":"https://git.kernel.org/stable/c/9f1e40193eef7f047e6b77cfb4b4cafdecd7a123"}],"title":"apparmor: fix out-of-bounds write when null terminating a label vec","x_generator":{"engine":"bippy-1.2.0"}}}}