CVE-2026-45893
📛 CVE Title
apparmor: Fix & Optimize table creation from possibly unaligned memory
Description
In the Linux kernel, the following vulnerability has been resolved: apparmor: Fix & Optimize table creation from possibly unaligned memory Source blob may come from userspace and might be unaligned. Try to optize the copying process by avoiding unaligned memory accesses. - Added Fixes tag - Added "Fix &" to description as this doesn't just optimize but fixes a potential unaligned memory access [jj: remove duplicate word "convert" in comment trigger checkpatch warning]
Overview
- State
- PUBLISHED
- Assigner (CNA)
- Linux
- CVSS severity
- high
- CVSS score
- 7.1 / 10
- CVSS vector
AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H- Effective score
- 7.1 / 10 HIGH source: CNA overview
- MSRC score
- 3.3 / 10 LOW MS rating: Low
- CWE(s)
-
CWE-125 - Reserved
- 2026-05-13
- Published
- 2026-05-27 12:17 UTC
- Last updated
- 2026-05-27 12:17 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/45xxx/CVE-2026-45893.json
- Linked Threat
- CVE-2026-45893 — CVE-2026-45893
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-05-27 14:17:03 UTC
- NVD last modified
- 2026-06-25 21:10:15 UTC
- NVD CVSS v3.1
- 7.1 / 10 HIGH source: nvd@nist.gov
- NVD CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H- Exploitability subscore
- 1.8 / 10
- Impact subscore
- 5.2 / 10
- EPSS score
- 0.0013 (probability of exploitation in next 30 days)
- EPSS percentile
- 2.61% vs all CVEs — higher = more likely to be exploited, as of 2026-07-26
NVD / KEV / EPSS data refreshed 2026-07-27 11:52 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-32359 - Assigner
- Linux
- Published
- May 27, 2026, 12:17:04 PM
- Updated
- May 27, 2026, 12:17:04 PM
- EUVD base score
- 0.0 / 10
- EUVD-reported EPSS
- 0.1300
- Vendors
- Linux
- Products
-
Linux (patch: 6.19.4)Linux (patch: 7.0)Linux (patch: 6.12.75)Linux (4.11)Linux (patch: 0)Linux (e6e8bf418850d7958311a96ccfb594f2bcc8313e <226c3b10aab23f73b03c47e7773107de56ba3a4e)Linux (e6e8bf418850d7958311a96ccfb594f2bcc8313e <e027999049c493fb728ead5a90db76942181a935)Linux (patch: 6.18.14)Linux (e6e8bf418850d7958311a96ccfb594f2bcc8313e <47e351dfef60ab0e3285133556e1a9c7f646a969)Linux (e6e8bf418850d7958311a96ccfb594f2bcc8313e <6fc367bfd4c8886e6b1742aabbd1c0bdc310db3a)
- Aliases
-
GHSA-44ww-rw32-794r
ENISA description: In the Linux kernel, the following vulnerability has been resolved: apparmor: Fix & Optimize table creation from possibly unaligned memory Source blob may come from userspace and might be unaligned. Try to optize the copying process by avoiding unaligned memory accesses. - Added Fixes tag - Added "Fix &" to description as this doesn't just optimize but fixes a potential unaligned memory access [jj: remove duplicate word "convert" in comment trigger checkpatch warning]
EUVD references (4)
Microsoft Security Response Center MSRC
Microsoft's vendor-authoritative record from the Security Update Guide — its own CVSS score, impact, severity rating, exploit assessment, and KB-article fixes. Refreshed 2026-08-12 01:09 UTC (source: CVRF).
- MS severity
- Low
- MS CVSS base score
- 3.3 / 10 (temporal 3.1)
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:U - Release
- 2026-May
Affected products (2)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Linux | Linux |
e6e8bf418850d7958311a96ccfb594f2bcc8313e (affected),
e6e8bf418850d7958311a96ccfb594f2bcc8313e (affected),
e6e8bf418850d7958311a96ccfb594f2bcc8313e (affected),
e6e8bf418850d7958311a96ccfb594f2bcc8313e (affected)
|
— |
| Linux | Linux |
4.11 (affected),
0 (unaffected),
6.12.75 (unaffected),
6.18.14 (unaffected),
6.19.4 (unaffected),
7.0 (unaffected)
|
— |
Affected products — CPE 2.3 (1) NVD
NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendor references (4)
References embedded in the original CVE record by the assigning CNA.
Web references (8)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- MSRC update guide: CVE-2026-45893 msrc
- https://git.kernel.org/stable/c/47e351dfef60ab0e3285133556e1a9c7f646a969 tenable:git.kernel.org
- https://git.kernel.org/stable/c/6fc367bfd4c8886e6b1742aabbd1c0bdc310db3a tenable:git.kernel.org
- https://git.kernel.org/stable/c/e027999049c493fb728ead5a90db76942181a935 tenable:git.kernel.org
- https://nvd.nist.gov/vuln/detail/CVE-2026-45893 tenable:nvd.nist.gov
- https://www.cve.org/CVERecord?id=CVE-2026-45893 tenable:www.cve.org
- https://git.kernel.org/stable/c/226c3b10aab23f73b03c47e7773107de56ba3a4e tenable:git.kernel.org
- https://www.first.org/epss/ tenable:www.first.org
NVD-tagged references (4)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://git.kernel.org/stable/c/226c3b10aab23f73b03c47e7773107de56ba3a4e 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Patch
- https://git.kernel.org/stable/c/47e351dfef60ab0e3285133556e1a9c7f646a969 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Patch
- https://git.kernel.org/stable/c/6fc367bfd4c8886e6b1742aabbd1c0bdc310db3a 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Patch
- https://git.kernel.org/stable/c/e027999049c493fb728ead5a90db76942181a935 416baaa9-dc9f-4396-8d5f-8c081fb06d67 Patch
Remediations (17)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:blog.gridinsoft.com
CVE - 2026 -41089 in Windows Netlogon is now reported as actively exploited. Patch domain controllers and check LSASS, Netlogon, and authentication logs.
2026-06-04 00:16 UTC -
web:cybersecuritynews.com
Microsoft's May 2026 Patch Tuesday lands with a heavy enterprise focus, fixing 120 vulnerabilities across Windows, Office, Azure, developer tools, and Microsoft 365 apps, including 29 remote code execution (RCE) flaws rated Critical.
2026-06-04 00:16 UTC -
web:dailysecurityreview.com
Belgium's CCB confirmed active exploitation of CVE - 2026 -41089, a CVSS 9.8 unauthenticated Windows Netlogon RCE affecting all supported Windows Server versions.
2026-06-04 00:16 UTC -
web:orca.security
Critical Netlogon RCE CVE - 2026 -41089 puts Windows Server domain controllers at risk. Use Orca Security to detect unpatched instances and protect your AD.
2026-06-04 00:16 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-06-04 00:16 UTC -
web:securityarsenal.com
A critical CVSS 9.8 flaw in Windows Netlogon allows SYSTEM-level code execution on Domain Controllers. Immediate patching is required.
2026-06-04 00:16 UTC -
web:thecyberexpress.com
Threat actors are reportedly exploiting CVE - 2026 -41089, a critical Windows Netlogon vulnerability enabling unauthenticated remote code execution.
2026-06-04 00:16 UTC -
web:windowsreport.com
Belgium's cybersecurity agency warns attackers are actively exploiting the critical Windows Netlogon vulnerability CVE - 2026 -41089.
2026-06-04 00:16 UTC -
web:www.bleepingcomputer.com
The Centre for Cybersecurity Belgium (CCB), the country's national authority for cybersecurity, warned on Friday that threat actors are now exploiting a recently patched critical Windows Netlogon ...
2026-06-04 00:16 UTC -
web:www.helpnetsecurity.com
CVE - 2026 -41089, a critical Windows Netlogon RCE flaw that allows remote code execution, is now actively exploited in the wild.
2026-06-04 00:16 UTC -
web:cybersecuritynews.com
Microsoft has officially acknowledged a critical zero-day vulnerability in Microsoft Defender, publicly dubbed "RoguePlanet," and confirmed it is actively developing a security patch to address the flaw.
2026-06-19 02:27 UTC -
web:msrc.microsoft.com
Security Update Guide - Microsoft Security Response Center
2026-06-19 02:27 UTC -
web:support.microsoft.com
Applies to: Windows Server 2019 This security update includes fixes and quality improvements that are part of the following update: May 12, 2026—KB5087538 (OS Build 17763.8755) The following is a summary of the issues that this update addresses when you install this update. The bold text within the brackets indicates the item or area of the change we are documenting. [Secure Boot] This ...
2026-06-19 02:27 UTC -
web:support.microsoft.com
The following summary outlines key issues addressed by this update. The bold text within the brackets indicates the item or area of the change. [Networking] Fixed: This update addresses a security issue in the Windows Routing and Remote Access Service (RRAS) management tool. If you connect to a malicious remote server, an attacker could disrupt the tool or run code on your device. For more ...
2026-06-19 02:27 UTC -
web:www.malwarebytes.com
Microsoft says it's working on a fix for an unpatched Defender vulnerability that can give attackers the highest level of access on Windows.
2026-06-19 02:27 UTC -
web:www.secpod.com
A working PoC for CVE - 2026 -41089 appeared on GitHub within 24 hours of Microsoft's May 12 disclosure. Active exploitation in the wild was confirmed 20 days later. This part covers how the public exploit operates, what in-the-wild activity looks like, and the compounding risk this vulnerability creates across Windows Netlogon and Active Directory environments.
2026-06-19 02:27 UTC -
web:www.tanium.com
A critical Netlogon RCE flaw ( CVE - 2026 -41089) allows unauthenticated attackers to target domain controllers. Here's what to know and how to patch .
2026-06-19 02:27 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-45893.json.
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"security/apparmor/include/match.h",
"security/apparmor/match.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "47e351dfef60ab0e3285133556e1a9c7f646a969",
"status": "affected",
"version": "e6e8bf418850d7958311a96ccfb594f2bcc8313e",
"versionType": "git"
},
{
"lessThan": "e027999049c493fb728ead5a90db76942181a935",
"status": "affected",
"version": "e6e8bf418850d7958311a96ccfb594f2bcc8313e",
"versionType": "git"
},
{
"lessThan": "226c3b10aab23f73b03c47e7773107de56ba3a4e",
"status": "affected",
"version": "e6e8bf418850d7958311a96ccfb594f2bcc8313e",
"versionType": "git"
},
{
"lessThan": "6fc367bfd4c8886e6b1742aabbd1c0bdc310db3a",
"status": "affected",
"version": "e6e8bf418850d7958311a96ccfb594f2bcc8313e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"security/apparmor/include/match.h",
"security/apparmor/match.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.11"
},
{
"lessThan": "4.11",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.75",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.14",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.75",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.14",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.4",
"versionStartIncluding": "4.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "4.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: Fix & Optimize table creation from possibly unaligned memory\n\nSource blob may come from userspace and might be unaligned.\nTry to optize the copying process by avoiding unaligned memory accesses.\n\n- Added Fixes tag\n- Added \"Fix &\" to description as this doesn't just optimize but fixes\n a potential unaligned memory access\n[jj: remove duplicate word \"convert\" in comment trigger checkpatch warning]"
}
],
"providerMetadata": {
"dateUpdated": "2026-05-27T12:17:04.135Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/47e351dfef60ab0e3285133556e1a9c7f646a969"
},
{
"url": "https://git.kernel.org/stable/c/e027999049c493fb728ead5a90db76942181a935"
},
{
"url": "https://git.kernel.org/stable/c/226c3b10aab23f73b03c47e7773107de56ba3a4e"
},
{
"url": "https://git.kernel.org/stable/c/6fc367bfd4c8886e6b1742aabbd1c0bdc310db3a"
}
],
"title": "apparmor: Fix & Optimize table creation from possibly unaligned memory",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-45893",
"datePublished": "2026-05-27T12:17:04.135Z",
"dateReserved": "2026-05-13T15:03:33.083Z",
"dateUpdated": "2026-05-27T12:17:04.135Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}