PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-47335 Canonical CVE debrief

A NULL pointer dereference vulnerability exists in Ubuntu Linux 6.8 within SAUCE patches handling AppArmor notifications. An unprivileged local user can trigger this flaw to cause a kernel panic, resulting in denial of service. The vulnerability was disclosed on 2026-05-28 with a CVSS 3.1 score of 5.5 (MEDIUM severity). The issue is tracked as CWE-476 (NULL Pointer Dereference). The vulnerability affects the Ubuntu kernel's AppArmor notification subsystem, specifically within SAUCE (Ubuntu-specific) patches. No known exploitation in the wild or ransomware campaign use has been reported. The fix is available via a kernel commit in the Ubuntu noble repository.

Vendor
Canonical
Product
Ubuntu Linux
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-28
Original CVE updated
2026-05-29
Advisory published
2026-05-28
Advisory updated
2026-05-29

Who should care

System administrators running Ubuntu 6.8 kernels with AppArmor enabled; security teams managing Ubuntu server and workstation fleets; kernel maintainers tracking Ubuntu-specific SAUCE patch security issues

Technical summary

The vulnerability resides in SAUCE patches for AppArmor notifications in Ubuntu Linux 6.8. A missing NULL check allows an unprivileged local attacker to dereference a NULL pointer, triggering a kernel panic. The attack requires local access but no user interaction. The CVSS 3.1 vector (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) reflects high availability impact with no confidentiality or integrity impact. The fix involves proper NULL pointer validation in the AppArmor notification handling code path.

Defensive priority

medium

Recommended defensive actions

  • Apply the kernel patch from the Ubuntu noble repository commit referenced in the security advisory
  • Update to a fixed Ubuntu kernel version once released through standard distribution channels
  • Monitor Ubuntu Security Notices (USN) for official security update availability
  • Review systems running Ubuntu 6.8 kernel with AppArmor enabled for unexpected stability issues
  • Consider restricting unprivileged user access to AppArmor notification interfaces as a temporary mitigation where feasible

Evidence notes

Vulnerability description sourced from official CVE record and NVD entry. CVSS vector confirms local attack vector with low attack complexity. Weakness classification (CWE-476) provided by [email protected]. Vendor attribution to Ubuntu derived from Launchpad git repository reference and kernel source path.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-47335 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-47335

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-47335 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47335

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.