{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-90231","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.794Z","datePublished":"2026-09-17T16:07:38.613Z","dateUpdated":"2026-09-18T17:53:59.067Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-18T17:53:59.067Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: fix unconfined user namespace restriction forced stack\n\nIf a task is already confined by a stack the unprivileged transition\nrestriction on unconfined is not correctly, applied. This results in\nan escape if two transitions through an unconfined profile can be\nexecuted.\n\nFix this by pushing the check into the per profile label build. The\ncheck will always be done against unconfined and result in a stack of\njust the unconfined component when necessary."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","baseScore":8.4,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The attacker reaches aa_change_profile() by writing a changeprofile or exec command to /proc/self/attr/current or /proc/self/attr/exec (proc_pid_attr_write → apparmor_setprocattr → do_setattr) or via lsm_set_self_attr(2); the profile name is local process input, not a remote protocol message.\nAC:L - Success is two attacker-driven writes plus execve. The vulnerable gate is the pointer test label == &labels_ns(label)->unconfined->label in aa_change_profile(), so the first transition off the ns unconfined sentinel makes the second skip forced stacking; change_profile_perms() allows any target from a profile_unconfined() component, with no race.\nPR:L - Writing /proc/self/attr/current or /proc/self/attr/exec requires only that the opener is current (proc_pid_attr_write); there is no capable() check. The intended victims are tasks that fail cap_capable(current_cred(), &init_user_ns, CAP_MAC_OVERRIDE), so a plain unprivileged local user, including one with caps only in a user namespace, suffices.\nUI:N - The attacker opens and writes their own /proc/self/attr/current or /proc/self/attr/exec, then execve()s to apply AA_CHANGE_ONEXEC; no other user must mount media, open a file, or confirm the transition.\nS:C - fn_label_build_in_scope() then aa_replace_current_label() drop the stacked ns unconfined profile that AppArmor was using as the MAC authority on the task, so later hooks (apparmor_userns_create, file mediation) run outside the policy that stack was required to keep applied—an AppArmor policy/sandbox escape.\nC:H - After the second aa_change_profile()/handle_onexec() build, the task’s label no longer includes ns unconfined, so AppArmor no longer denies reads a stacked or confined profile would have blocked, and a remaining FLAG_UNCONFINED label skips apparmor_userns_create() mediation, exposing userns-gated kernel interfaces the restriction was meant to hide.\nI:H - The same aa_replace_current_label() replacement lets the task perform writes and capability-using operations AppArmor was mediating, including unshare(CLONE_NEWUSER) from a FLAG_UNCONFINED profile, yielding CAP_SYS_ADMIN/CAP_NET_ADMIN in that namespace—the integrity of the MAC policy the forced stack was supposed to preserve.\nA:N - The flaw only skips the forced-stack conversion in aa_change_profile()/handle_onexec(); it does not dereference invalid pointers, corrupt memory, or trigger BUG_ON, oops, panic, or deadlock."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["security/apparmor/domain.c"],"versions":[{"version":"2d9da9b188b8cd3b579d7ef5ba5d334be9dd38fc","lessThan":"7d1099b86356df81c379159bfb8a598aaf83ce81","status":"affected","versionType":"git"},{"version":"2d9da9b188b8cd3b579d7ef5ba5d334be9dd38fc","lessThan":"7da0bdf0610f6d35bbb061536a47fc41646306f0","status":"affected","versionType":"git"},{"version":"2d9da9b188b8cd3b579d7ef5ba5d334be9dd38fc","lessThan":"08c2f7c8d4b1434cfae006f3daf4d1bce330b57b","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["security/apparmor/domain.c"],"versions":[{"version":"6.7","status":"affected"},{"version":"0","lessThan":"6.7","status":"unaffected","versionType":"semver"},{"version":"6.18.52","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.6","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.7","versionEndExcluding":"6.18.52"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.7","versionEndExcluding":"7.2.6"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.7","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/7d1099b86356df81c379159bfb8a598aaf83ce81"},{"url":"https://git.kernel.org/stable/c/7da0bdf0610f6d35bbb061536a47fc41646306f0"},{"url":"https://git.kernel.org/stable/c/08c2f7c8d4b1434cfae006f3daf4d1bce330b57b"}],"title":"apparmor: fix unconfined user namespace restriction forced stack","x_generator":{"engine":"bippy-1.2.0"}}}}