From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BAB4237F00D for ; Sat, 15 Aug 2026 06:31:11 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786775472; cv=none; b=Qd9epgjrdzIzqDF/eR+T7c/mBJgN4Upe4iJrth0BBFIwax9BdBmmQtV96lgbNg5/io0G3aFSkCsgV/LoVzgT0gq+QVRfrylH/CVpOUJWEiJ+NvQ20Ex4NZFOvTNX7r6GebJQSqwNhHSWhpLFS9o0HgrILJznihNiVOwze+Ja8II= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786775472; c=relaxed/simple; bh=4+YuDnxG82R2Wot4r76S6+UHzyS6Cs3m4vt/ddF4RYY=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=Go95AMK0JRgjcPVhSj8IX/MKe8wNTZ0yuPXrtd3D5UxCqWY67LxrLICKxDf0PZS6ROCbeS2jzPItat5E1wPuRFHs4Sr7jRNPwRHIs13BeTHCUEHLDAT253WG49IidGc1Qr4w16qGdrXHUpkLaQrbE5XkLnwL/yXuwWBWu+LGBuA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=UWkGNyuH; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="UWkGNyuH" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 12F4A1F000E9; Sat, 15 Aug 2026 06:31:10 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1786775471; bh=EKLn0Frd3weqAXfb8Mb8X1yvc2U4BzNzLkmUAQjy8Oo=; h=From:To:Cc:Subject:Date:Reply-To; b=UWkGNyuHaZf4WIQzlu8sqghbACR0R20K177a4VhY7kNunhqtMtbxahMLtvVG9CD8O 50MBgWbwhGsPyRiLWaoQlaJw15BHdlSR/ettySCghTvYbqXK0DmukhnIIRQb//KRPS Ui+DkV90WI1BY4cUwTbDIyG/e6EzUieLPgouS8Bo= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-72459: apparmor: aa_label_alloc use aa_label_free on alloc failure Date: Sat, 15 Aug 2026 15:08:58 +0900 Message-ID: <2026081532-CVE-2026-72459-cda8@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3515; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=12K4ObE7ZeUDb1T4EdqQ+x97uL2AuC2t9xmmm0YHun4=; b=owGbwMvMwCRo6H6F97bub03G02pJDFkNDD83u3bkT1I2UXCp5f/1oPRtkmnTonvxajc7dmbk9 lRE+ul3xLIwCDIxyIopsnzZxnN0f8UhRS9D29Mwc1iZQIYwcHEKwER+dzEsOLns8tptD59X/iqr Uzm4bcpDt8jiywxzpf8vmupWZrCy9egah60V/5+2nXx4BwA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: apparmor: aa_label_alloc use aa_label_free on alloc failure aa_label_alloc() allocates a secid before allocating or taking the label proxy. If the later proxy step fails, the error path only freed the label memory, leaking any resources initialized by aa_label_init(). Use aa_label_free() on the failure path so partially initialized labels release their secid and other label resources before the backing memory is freed. The Linux kernel CVE team has assigned CVE-2026-72459 to this issue. Affected and fixed versions =========================== Issue introduced in 4.13 with commit f1bd904175e8190ce14aedee37e207ab51fe3b30 and fixed in 5.10.261 with commit b14fbacad77d64594228983ec20d61a224f3f491 Issue introduced in 4.13 with commit f1bd904175e8190ce14aedee37e207ab51fe3b30 and fixed in 5.15.212 with commit b5a9da5d36162d34db0f36abb15420e295176793 Issue introduced in 4.13 with commit f1bd904175e8190ce14aedee37e207ab51fe3b30 and fixed in 6.1.178 with commit 7cb69e109610bba500e1ecb870f7988a4717208a Issue introduced in 4.13 with commit f1bd904175e8190ce14aedee37e207ab51fe3b30 and fixed in 6.6.145 with commit cc2192899d502e3321e60cf1e91421e7309d089c Issue introduced in 4.13 with commit f1bd904175e8190ce14aedee37e207ab51fe3b30 and fixed in 6.12.97 with commit bf310b044e85d4de670c94295c5d8e4c5bc5e7bc Issue introduced in 4.13 with commit f1bd904175e8190ce14aedee37e207ab51fe3b30 and fixed in 6.18.40 with commit ae02e603c0b39b29f3ce6fe3efe01b286af1a2a4 Issue introduced in 4.13 with commit f1bd904175e8190ce14aedee37e207ab51fe3b30 and fixed in 7.1.5 with commit 6d91479174240f39e9edea250d95fa08c678a207 Issue introduced in 4.13 with commit f1bd904175e8190ce14aedee37e207ab51fe3b30 and fixed in 7.2-rc1 with commit 654fe7505dc6889724d4094fa64f89991afabfc3 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-72459 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: security/apparmor/label.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/b14fbacad77d64594228983ec20d61a224f3f491 https://git.kernel.org/stable/c/b5a9da5d36162d34db0f36abb15420e295176793 https://git.kernel.org/stable/c/7cb69e109610bba500e1ecb870f7988a4717208a https://git.kernel.org/stable/c/cc2192899d502e3321e60cf1e91421e7309d089c https://git.kernel.org/stable/c/bf310b044e85d4de670c94295c5d8e4c5bc5e7bc https://git.kernel.org/stable/c/ae02e603c0b39b29f3ce6fe3efe01b286af1a2a4 https://git.kernel.org/stable/c/6d91479174240f39e9edea250d95fa08c678a207 https://git.kernel.org/stable/c/654fe7505dc6889724d4094fa64f89991afabfc3