CVE-2026-23268Disclosure(linux / linux_kernel)

HIGHCVSS 7.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch linux linux_kernel systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix unprivileged local user can do privileged policy management An unprivileged local user can load, replace, and remove profiles by opening the apparmorfs interfaces, via a confused deputy attack, by passing the opened fd to a privileged process, and getting the privileged process to write to the interface. This does require a privileged target that can be manipulated to do the write for the unprivileged process, but once such access is achieved full policy management is possible and all the possible implications that implies: removing confinement, DoS of system or target applications by denying all execution, by-passing the unprivileged user namespace restriction, to exploiting kernel bugs for a local privilege escalation. The policy management interface can not have its permissions simply changed from 0666 to 0600 because non-root processes need to be able to load policy to different policy namespaces. Instead ensure the task writing the interface has privileges that are a subset of the task that opened the interface. This is already done via policy for confined processes, but unconfined can delegate access to the opened fd, by-passing the usual policy check.

7.5/ 10 priority

Sources & remediation

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 9 mentions across 7 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked 6d ago at 2 mentions (2026-03-18); latest day: 1
  • 9 total mentions across 7 days

Affected systems

Vendors
Products
linux_kernel

1 version affected across 1 product

Deep dive

Activity timeline9 mentions / 7d
01122Mentions · 2026-03-18: 2Mentions · 2026-03-19: 2Mentions · 2026-03-28: 1Mentions · 2026-04-20: 1Mentions · 2026-04-24: 1Mentions · 2026-04-27: 1Mentions · 2026-09-23: 1PoC Mentioned / Linked · 2026-09-23: 1Exploit Tool / Code · 2026-09-23: 1Active Exploitation · 2026-03-19: 1Patch / Workaround · 2026-03-18: 1Patch / Workaround · 2026-03-28: 1Patch / Workaround · 2026-04-27: 1Technical Details · 2026-03-18: 1Technical Details · 2026-04-24: 1Technical Details · 2026-04-27: 103-1803-1903-2804-2004-2404-2709-23
Signal classification4 categories
Disclosure
444.4%
Patch
333.3%
Active Exploitation
111.1%
Exploit
111.1%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-03-182
Disclosure1Patch1
2026-03-192
Active Exploitation1Disclosure1
2026-03-281
Patch1
2026-04-201
Disclosure1
2026-04-241
Disclosure1
2026-04-271
Patch1
2026-09-231
Exploit1
Full discourse9 posts
  • portbuster@portbuster1337
    Exploit

    lpe-toolkit has been updated with new LPE exploits! New exploits added: - RefluXFS CVE-2026-64600 - CrackArmor CVE-2026-23268 - skb_shift CVE-2026-43503 - GRO Flag Loss CVE-2026-43503 - snap-confine CVE-2026-8933 https://github.com/portbuster1337/lpe-toolkit/releases/tag/v1.4.0

    Post summary

    The tweet announces an update to the lpe-toolkit, a Linux privilege escalation exploit toolkit, adding new exploits for several CVEs, with source code available in the linked release.

    0230111668.5K
    366 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Stop chasing kernel CVEs like it's 2026. CVE-2026-23191 (ALSA race) and CVE-2026-23268 (AppArmor bypass) are already patched. But the NEXT one? Read more -> https://tinyurl.com/2hm6nwnt #SUSE https://t.co/tqVyQDUyvQ

    Post summary

    The tweet confirms that CVE‑2026‑23191 and CVE‑2026‑23268 have been patched, offers no proof of concept or exploit details, and asks what the next vulnerability to address will be.

    1000049
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    CVE-2026-23191 (kernel race condition) and CVE-2026-23268 (AppArmor bypass) are classic privilege escalation flaws. Read more: -> https://tinyurl.com/43zmt7n8 https://t.co/5nC0AuhVds

    Post summary

    The tweet announces two new privilege escalation CVEs, a kernel race condition and an AppArmor bypass, and directs readers to a link for additional details.

    1000050
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    Stop chasing CVEs. Start mastering Linux security. The latest kernel bugs (CVE-2025-40309 + CVE-2026-23268) exploit the SAME patterns from 5 years ago. Read more -> https://tinyurl.com/bdfb46z6 #SUSE https://t.co/f0phFKg9WA

    Post summary

    The tweet announces two new Linux kernel CVEs, noting they reuse patterns from five years ago, and directs readers to a link for further details, but provides no deeper technical or exploit information.

    10000265
    1.5K followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    A lot of offensive activities were identified targeting Linux Kernel (CVE-2026-23268) https://vuldb.com/?ctiid.351581

    Post summary

    Multiple offensive operations targeting CVE-2026-23268 on Linux Kernel have been identified, indicating it is actively exploited in the wild.

    0000181
    2.1K followersView on X
  • Brad Spengler@spendergrsec
    Disclosure

    Two now finally (why two?): https://lore.kernel.org/linux-cve-announce/2026031846-CVE-2026-23268-6be3@gregkh/T/#u https://lore.kernel.org/linux-cve-announce/2026031846-CVE-2026-23269-2bf7@gregkh/T/#u

    Post summary

    The message shares two URLs to kernel.org CVE announcements for CVE-2026-23268 and CVE-2026-23269, with no additional detail beyond the links.

    00010228
    4.4K followersView on X
  • GCP Weekly@gcpweekly
    Patch

    Compute Engine update on March 27, 2026 https://docs.cloud.google.com/compute/docs/release-notes#March_27_2026 #googlecloud A vulnerability (CVE-2026-23268) about CrackArmor was discovered and has been addressed. For more information, see the GCP-2026-015 security bulletin.

    Post summary

    Google disclosed that CVE-2026-23268, a vulnerability in CrackArmor, has been fixed and directs readers to the GCP‑2026‑015 security bulletin for details.

    00000104
    1.8K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in Linux Kernel (CVE-2026-23268) https://vuldb.com/?id.351581

    Post summary

    The text announces a new Linux Kernel vulnerability (CVE‑2026‑23268) but provides no technical details, PoC, or patch information.

    0000073
    2.1K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-23268 In the Linux kernel, the following vulnerability has been resolved: apparmor: fix unprivileged local user can do privileged policy management An unprivileged local … https://www.cve.org/CVERecord?id=CVE-2026-23268

    Post summary

    CVE-2026-23268, a Linux kernel flaw allowing unprivileged local users to manage AppArmor policies, has been resolved—indicating a patch, though no PoC, exploit or exploitation details are included in the text.

    0000097
    56.8K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more