linux-azure, linux-azure-fips, linux-oracle vulnerabilities
Qualys discovered that several vulnerabilities existed in the AppArmor Linux kernel Security Module (LSM). An unprivileged local attacker could use these issues to load, replace, and remove arbitrary AppArmor profiles causing denial of service, exposure of sensitive information (kernel memory), local privilege escalation, or possibly escape a container. (LP: #2143853, CVE-2026-23268, CVE-2026-23269, CVE-2026-23403, CVE-2026-23404, CVE-2026-23405, CVE-2026-23410, CVE-2026-23411) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - Cryptographic API; - GPU drivers; - Network drivers; - UDF file system; - NFC subsystem; - Network traffic control; - Sun RPC protocol; - XFRM subsystem; (CVE-2024-27388, CVE-2024-46777, CVE-2024-46816, CVE-2024-49938, CVE-2024-50008, CVE-2024-50142, CVE-2025-21735, CVE-2025-37849, CVE-2026-23060, CVE-2026-23074, CVE-2026-23209)
02 / AFFECTED SOFTWARE
Affected packages
137 explicit affected versions
107 explicit affected versions
80 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Qualys discovered that several vulnerabilities existed in the AppArmor Linux kernel Security Module (LSM). An unprivileged local attacker could use these issues to load, replace, and remove arbitrary AppArmor profiles causing denial of service, exposure of sensitive information (kernel memory), local privilege escalation, or possibly escape a container. (LP: #2143853, CVE-2026-23268, CVE-2026-23269, CVE-2026-23403, CVE-2026-23404, CVE-2026-23405, CVE-2026-23410, CVE-2026-23411) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture; - Cryptographic API; - GPU drivers; - Network drivers; - UDF file system; - NFC subsystem; - Network traffic control; - Sun RPC protocol; - XFRM subsystem; (CVE-2024-27388, CVE-2024-46777, CVE-2024-46816, CVE-2024-49938, CVE-2024-50008, CVE-2024-50142, CVE-2025-21735, CVE-2025-37849, CVE-2026-23060, CVE-2026-23074, CVE-2026-23209)
05 / REFERENCES
Further evidence
- https://launchpad.net/bugs/2143853
- https://ubuntu.com/security/CVE-2024-27388
- https://ubuntu.com/security/CVE-2024-46777
- https://ubuntu.com/security/CVE-2024-46816
- https://ubuntu.com/security/CVE-2024-49938
- https://ubuntu.com/security/CVE-2024-50008
- https://ubuntu.com/security/CVE-2024-50142
- https://ubuntu.com/security/CVE-2025-21735
- https://ubuntu.com/security/CVE-2025-37849
- https://ubuntu.com/security/CVE-2026-23060
- https://ubuntu.com/security/CVE-2026-23074
- https://ubuntu.com/security/CVE-2026-23209
- https://ubuntu.com/security/CVE-2026-23268
- https://ubuntu.com/security/CVE-2026-23269
- https://ubuntu.com/security/CVE-2026-23403
- https://ubuntu.com/security/CVE-2026-23404
- https://ubuntu.com/security/CVE-2026-23405
- https://ubuntu.com/security/CVE-2026-23410
- https://ubuntu.com/security/CVE-2026-23411
- https://ubuntu.com/security/notices/USN-8267-1