{"id":"AZL-89342","summary":"CVE-2026-46254 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nAppArmor: Allow apparmor to handle unaligned dfa tables\n\nThe dfa tables can originate from kernel or userspace and 8-byte alignment\nisn't always guaranteed and as such may trigger unaligned memory accesses\non various architectures. Resulting in the following\n\n[   73.901376] WARNING: CPU: 0 PID: 341 at security/apparmor/match.c:316 aa_dfa_unpack+0x6cc/0x720\n[   74.015867] Modules linked in: binfmt_misc evdev flash sg drm drm_panel_orientation_quirks backlight i2c_core configfs nfnetlink autofs4 ext4 crc16 mbcache jbd2 hid_generic usbhid sr_mod hid cdrom\nsd_mod ata_generic ohci_pci ehci_pci ehci_hcd ohci_hcd pata_ali libata sym53c8xx scsi_transport_spi tg3 scsi_mod usbcore libphy scsi_common mdio_bus usb_common\n[   74.428977] CPU: 0 UID: 0 PID: 341 Comm: apparmor_parser Not tainted 6.18.0-rc6+ #9 NONE\n[   74.536543] Call Trace:\n[   74.568561] [\u003c0000000000434c24\u003e] dump_stack+0x8/0x18\n[   74.633757] [\u003c0000000000476438\u003e] __warn+0xd8/0x100\n[   74.696664] [\u003c00000000004296d4\u003e] warn_slowpath_fmt+0x34/0x74\n[   74.771006] [\u003c00000000008db28c\u003e] aa_dfa_unpack+0x6cc/0x720\n[   74.843062] [\u003c00000000008e643c\u003e] unpack_pdb+0xbc/0x7e0\n[   74.910545] [\u003c00000000008e7740\u003e] unpack_profile+0xbe0/0x1300\n[   74.984888] [\u003c00000000008e82e0\u003e] aa_unpack+0xe0/0x6a0\n[   75.051226] [\u003c00000000008e3ec4\u003e] aa_replace_profiles+0x64/0x1160\n[   75.130144] [\u003c00000000008d4d90\u003e] policy_update+0xf0/0x280\n[   75.201057] [\u003c00000000008d4fc8\u003e] profile_replace+0xa8/0x100\n[   75.274258] [\u003c0000000000766bd0\u003e] vfs_write+0x90/0x420\n[   75.340594] [\u003c00000000007670cc\u003e] ksys_write+0x4c/0xe0\n[   75.406932] [\u003c0000000000767174\u003e] sys_write+0x14/0x40\n[   75.472126] [\u003c0000000000406174\u003e] linux_sparc_syscall+0x34/0x44\n[   75.548802] ---[ end trace 0000000000000000 ]---\n[   75.609503] dfa blob stream 0xfff0000008926b96 not aligned.\n[   75.682695] Kernel unaligned access at TPC[8db2a8] aa_dfa_unpack+0x6e8/0x720\n\nWork around it by using the get_unaligned_xx() helpers.","modified":"2026-09-02T06:51:55Z","published":"2026-06-03T18:16:26Z","upstream":["CVE-2026-46254"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46254"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-89342.json"}}],"schema_version":"1.9.0"}