Description
Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitialized variable in notification handling code. The bug can be triggered by an unprivileged local user and can result in the incorrect caching of AppArmor notification responses.
Problem types
CWE-457 Use of uninitialized variable
Product status
6.8.0 (dpkg) before 6.8.0-124.124
6.17.0 (dpkg) before 6.17.0-35.35
7.0.0 (dpkg) before 7.0.0-22.22
Credits
Tristan Madani (@TristanInSec), Talence Security
References
git.launchpad.net/...b2c6eded493fa50e7c8cd3618d7ebe1358abaab