Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94407.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-94407
Upstream
Published
2026-07-29T14:16:35Z
Modified
2026-09-25T05:36:32Z
Summary
CVE-2026-67216 affecting package apparmor 3.1.7-1
Details

cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the function recurses into each shared subtree twice, once in each direction, with no depth guard, making the running time exponential in nesting depth. A small, deeply nested document of a few hundred bytes (depth around 40) compared for equality consumes hours of CPU, and the cost roughly doubles with each additional level of nesting. An application that calls cJSON_Compare() on attacker-influenced JSON that is structurally equal to a reference document is exposed to a denial-of-service condition.

References

Affected packages

Azure Linux:3 / apparmor

Package

Name
apparmor
Purl
pkg:rpm/azure-linux/apparmor

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
3.1.7-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94407.json"