Errata overview
Errata ID 42
Date 2018-05-16
Source package apparmor
Fixed in version 2.11.0-3+deb9u2
This update addresses the following issue:
* Pin the AppArmor feature set to Stretch's kernel. This ensures Stretch
  systems, even when running a newer kernel (e.g. from backports), have their
  AppArmor feature set pinned to the one supported by the AppArmor policy
  shipped in Stretch. Otherwise they would experience breakage due to new
  AppArmor mediation features introduced in recent kernels.
Additional notes
UCS Bug number #46628