CVE-2026-23404Patch(linux / linux_kernel)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linux linux_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: apparmor: replace recursive profile removal with iterative approach The profile removal code uses recursion when removing nested profiles, which can lead to kernel stack exhaustion and system crashes. Reproducer: $ pf='a'; for ((i=0; i<1024; i++)); do echo -e "profile $pf { \n }" | apparmor_parser -K -a; pf="$pf//x"; done $ echo -n a > /sys/kernel/security/apparmor/.remove Replace the recursive __aa_profile_list_release() approach with an iterative approach in __remove_profile(). The function repeatedly finds and removes leaf profiles until the entire subtree is removed, maintaining the same removal semantic without recursion.

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-01); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
linux_kernel

2 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-01: 2Mentions · 2026-04-10: 1Patch / Workaround · 2026-04-01: 1Patch / Workaround · 2026-04-10: 104-0104-10
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-012
Disclosure1Patch1
2026-04-101
Patch1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-23404 In the Linux kernel, the following vulnerability has been resolve... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-23404 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    A brief notification that CVE-2026-23404 has been resolved in the Linux kernel, with a reference link for more information.

    0000148
    4.0K followersView on X
  • WindowsForum@windowsforum
    Patch

    🛡️ AppArmor saving Linux from its own recursive doom. Meanwhile Microsoft will fix the symptom… after your server faceplants. Kernel hardening &gt; vibes, every time. #CVE #Security https://windowsforum.com/threads/cve-2026-23404-apparmor-kernel-fix-recursive-profile-removal-prevents-dos.411364/ #DenialOfService #ApparmorSecurity #Cve202623404 #LinuxKernelHardening

    Post summary

    The tweet highlights that Microsoft plans to release a fix for CVE‑2026‑23404, but offers no technical details or proof‑of‑concept, and does not discuss exploitation or alternative responses.

    0000035
    1.1K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-23404 In the Linux kernel, the following vulnerability has been resolved: apparmor: replace recursive profile removal with iterative approach The profile removal code use… https://www.cve.org/CVERecord?id=CVE-2026-23404

    Post summary

    The Linux kernel CVE‑2026‑23404 has been fixed by replacing the recursive profile removal method in AppArmor with an iterative approach, indicating the vulnerability has been patched.

    0000065
    56.9K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel2.6.36--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--
OSlinuxlinux_kernel7.0--

Explore more