HomeDefectsLIN1024-15752
Acknowledged

LIN1024-15752 : Security Advisory - linux - CVE-2026-23269

Created: Mar 19, 2026    Updated: Mar 31, 2026
Found In Version: 10.24.33.2
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:  apparmor: validate DFA start states are in bounds in unpack_pdb  Start states are read from untrusted data and used as indexes into the DFA state tables. The aa_dfa_next() function call in unpack_pdb() will access dfa->tables[YYTD_ID_BASE][start], and if the start state exceeds the number of states in the DFA, this results in an out-of-bound read.  ==================================================================  BUG: KASAN: slab-out-of-bounds in aa_dfa_next+0x2a1/0x360  Read of size 4 at addr ffff88811956fb90 by task su/1097  ...  Reject policies with out-of-bounds start states during unpacking to prevent the issue.