{"id":"CVE-2026-23403","summary":"apparmor: fix memory leak in verify_header","details":"In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: fix memory leak in verify_header\n\nThe function sets `*ns = NULL` on every call, leaking the namespace\nstring allocated in previous iterations when multiple profiles are\nunpacked. This also breaks namespace consistency checking since *ns\nis always NULL when the comparison is made.\n\nRemove the incorrect assignment.\nThe caller (aa_unpack) initializes *ns to NULL once before the loop,\nwhich is sufficient.","modified":"2026-04-02T03:30:31.727936Z","published":"2026-04-01T08:36:34.269Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23403.json","cna_assigner":"Linux"},"references":[{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"},{"type":"WEB","url":"https://git.kernel.org/stable/c/42fd831abfc15d0643c14688f0522556b347e7e6"},{"type":"WEB","url":"https://git.kernel.org/stable/c/4f0889f2df1ab99224a5e1ac4e20437eea5fe38e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/663ce34786e759ebcbeb3060685c20bcc886d51a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/786e2c2a87d9c505f33321d1fd23a176aa8ddeb1"},{"type":"WEB","url":"https://git.kernel.org/stable/c/e38c55d9f834e5b848bfed0f5c586aaf45acb825"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23403.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-23403"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"dd51c84857630e77c139afe4d9bba65fc051dc3f"},{"fixed":"663ce34786e759ebcbeb3060685c20bcc886d51a"},{"fixed":"786e2c2a87d9c505f33321d1fd23a176aa8ddeb1"},{"fixed":"4f0889f2df1ab99224a5e1ac4e20437eea5fe38e"},{"fixed":"42fd831abfc15d0643c14688f0522556b347e7e6"},{"fixed":"e38c55d9f834e5b848bfed0f5c586aaf45acb825"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23403.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.12.0"},{"fixed":"6.6.130"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.77"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.18"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"6.19.8"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23403.json"}}],"schema_version":"1.7.5"}