PatchSiren cyber security CVE debrief
CVE-2026-47335 Canonical CVE debrief
A NULL pointer dereference vulnerability exists in Ubuntu Linux 6.8 within SAUCE patches handling AppArmor notifications. An unprivileged local user can trigger this flaw to cause a kernel panic, resulting in denial of service. The vulnerability was disclosed on 2026-05-28 with a CVSS 3.1 score of 5.5 (MEDIUM severity). The issue is tracked as CWE-476 (NULL Pointer Dereference). The vulnerability affects the Ubuntu kernel's AppArmor notification subsystem, specifically within SAUCE (Ubuntu-specific) patches. No known exploitation in the wild or ransomware campaign use has been reported. The fix is available via a kernel commit in the Ubuntu noble repository.
- Vendor
- Canonical
- Product
- Ubuntu Linux
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-28
- Original CVE updated
- 2026-05-29
- Advisory published
- 2026-05-28
- Advisory updated
- 2026-05-29
Who should care
System administrators running Ubuntu 6.8 kernels with AppArmor enabled; security teams managing Ubuntu server and workstation fleets; kernel maintainers tracking Ubuntu-specific SAUCE patch security issues
Technical summary
The vulnerability resides in SAUCE patches for AppArmor notifications in Ubuntu Linux 6.8. A missing NULL check allows an unprivileged local attacker to dereference a NULL pointer, triggering a kernel panic. The attack requires local access but no user interaction. The CVSS 3.1 vector (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H) reflects high availability impact with no confidentiality or integrity impact. The fix involves proper NULL pointer validation in the AppArmor notification handling code path.
Defensive priority
medium
Recommended defensive actions
- Apply the kernel patch from the Ubuntu noble repository commit referenced in the security advisory
- Update to a fixed Ubuntu kernel version once released through standard distribution channels
- Monitor Ubuntu Security Notices (USN) for official security update availability
- Review systems running Ubuntu 6.8 kernel with AppArmor enabled for unexpected stability issues
- Consider restricting unprivileged user access to AppArmor notification interfaces as a temporary mitigation where feasible
Evidence notes
Vulnerability description sourced from official CVE record and NVD entry. CVSS vector confirms local attack vector with low attack complexity. Weakness classification (CWE-476) provided by [email protected]. Vendor attribution to Ubuntu derived from Launchpad git repository reference and kernel source path.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-47335 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-47335
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-47335 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47335
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.