HomeDefectsLIN1025-8800
Fixed

LIN1025-8800 : Security Advisory - linux - CVE-2026-23404

Created: Apr 2, 2026    Updated: Apr 8, 2026
Resolved Date: Apr 6, 2026
Found In Version: 10.25.33.2
Fix Version: 10.25.33.8
Severity: Standard
Applicable for: Wind River Linux LTS 25
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:  apparmor: replace recursive profile removal with iterative approach  The profile removal code uses recursion when removing nested profiles, which can lead to kernel stack exhaustion and system crashes.  Reproducer:   $ pf='a'; for ((i=0; i<1024; i++)); do       echo -e "profile $pf { \n }" | apparmor_parser -K -a;       pf="$pf//x";   done   $ echo -n a > /sys/kernel/security/apparmor/.remove  Replace the recursive __aa_profile_list_release() approach with an iterative approach in __remove_profile(). The function repeatedly finds and removes leaf profiles until the entire subtree is removed, maintaining the same removal semantic without recursion.