A vulnerability has been found in Linux Kernel up to 6.6.129/6.12.76/6.18.17/6.19.7/7.0-rc3 and classified as critical. Impacted is the function aa_replace_profiles of the component apparmor. The manipulation leads to double free.

This vulnerability is listed as CVE-2026-23408. The attack must be carried out from within the local network. There is no available exploit.

The affected component should be upgraded.