CyberRota Analysis
AI-GeneratedA vulnerability in the Linux kernel affects the AppArmor security module, specifically in the aa_change_profile() function, where improper handling of label building can lead to dereferencing an invalid label. This flaw may allow for privilege escalation or unauthorized access if exploited, as it bypasses critical checks for label validity. Organizations using Linux systems with AppArmor enabled should prioritize addressing this vulnerability to maintain system integrity and security.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: apparmor: check label build before no_new_privs test aa_change_profile() builds a replacement label with fn_label_build_in_scope() before the no_new_privs subset check. The build helper can fail and return NULL or an ERR_PTR, but the result was passed to aa_label_is_unconfined_subset() before the existing IS_ERR_OR_NULL() check. Reuse the existing target-label build failure handling immediately after the build. This preserves the current audit handling while preventing the subset helper from dereferencing an invalid label.