CVE-2026-23403 addresses a memory leak vulnerability within the Linux kernel's AppArmor component, specifically in the `verify_header` function. This flaw causes namespace strings to leak when multiple profiles are unpacked, additionally disrupting namespace consistency checking. While specific CVSS and FAUCET risk scores are unavailable, the issue primarily affects resource management and potential policy integrity rather than providing a direct path to remote code execution or privilege escalation. There is no evidence of active exploitation, no public exploit code is available, and community discussion remains limited to security mailing lists.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.12.1, < 5.10.253CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.15.203CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 6.1.169CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.6.130CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.7, < 6.12.77CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Linux kernel vulnerabilities
May 11, 2026Linux kernel vulnerabilities
May 11, 2026Linux kernel (Xilinx) vulnerabilities
May 7, 2026Linux kernel (Azure) vulnerabilities
May 7, 2026Linux kernel (BlueField) vulnerabilities
Apr 29, 2026Linux kernel (Azure) vulnerabilities
Apr 13, 2026Linux kernel (Azure FIPS) vulnerabilities
Apr 9, 2026Linux kernel (Intel IoTG Real-time) vulnerabilities
Apr 9, 2026Linux kernel (Azure FIPS) vulnerabilities
Apr 9, 2026Linux kernel (OEM) vulnerabilities
Apr 6, 2026apparmor: fix memory leak in verify_header
Apr 2, 2026