CVE-2026-80619
HIGH
Published Aug 28, 2026
Modified Aug 29, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix potential UAF in aa_replace_profiles The function aa_replace_profiles was accessing udata->size after calling aa_put_loaddata(udata), causing a potential UAF. Fixed this by saving the size to a local variable before dropping the reference.
Is your site exposed to CVE-2026-80619?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
7.8
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS — Exploit Prediction
0.0013
Probability of exploitation
0.03%
Percentile rank
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
References
Other References
https://git.kernel.org/stable/c/57b1bd4486d56254bb8af1a8f3d4445bbe505290
https://git.kernel.org/stable/c/5cba148eae6e8550c2889f5c0f94d72bed864321
https://git.kernel.org/stable/c/7b42f95813dc9ceb6bda35afcf914630909a19f9
https://git.kernel.org/stable/c/9d37dc6376e336dc4b4f39a7ad0d069aa70e9495
https://git.kernel.org/stable/c/9d8e47cbce7536f19c96e37d0685a042010187ee
https://git.kernel.org/stable/c/c0f3a3fda617beeec58708720304dd026a1a4dd7
https://git.kernel.org/stable/c/c44de0880b7ccc15c70a6352b5e107677d32b061
https://git.kernel.org/stable/c/dd5f1202f45a2dbe2c7dd10093f5c6bb2d8ac5bb
Frequently Asked Questions
What is CVE-2026-80619? +
In the Linux kernel, the following vulnerability has been resolved:
apparmor: fix potential UAF in aa_replace_profiles
The function aa_replace_profiles was accessing udata->size after calling
aa_put_loaddata(udata), causing a potential UAF.
Fixed this by saving the size to a local variable before dropping the
reference. It has a CVSS v3.1 base score of 7.8 (HIGH).
How severe is CVE-2026-80619? +
CVE-2026-80619 has a CVSS v3.1 score of 7.8 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching. The EPSS score is 0.0013, placing it in the 0th percentile for exploitation probability.
How do I check if I'm vulnerable to CVE-2026-80619? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.