A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.12.76/6.18.17/6.19.7/7.0-rc3. Impacted is the function aa_dfa_next of the component apparmor. The manipulation results in out-of-bounds read.

This vulnerability is identified as CVE-2026-23269. The attack can only be performed from the local network. There is not any exploit available.

It is advisable to upgrade the affected component.