All of lore.kernel.org
 help / color / mirror / Atom feed
* CVE-2026-72459: apparmor: aa_label_alloc use aa_label_free on alloc failure
@ 2026-08-15  6:08 Greg Kroah-Hartman
  0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-08-15  6:08 UTC (permalink / raw)
  To: linux-cve-announce; +Cc: Greg Kroah-Hartman

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

apparmor: aa_label_alloc use aa_label_free on alloc failure

aa_label_alloc() allocates a secid before allocating or taking the label
proxy. If the later proxy step fails, the error path only freed the label
memory, leaking any resources initialized by aa_label_init().

Use aa_label_free() on the failure path so partially initialized labels
release their secid and other label resources before the backing memory is
freed.

The Linux kernel CVE team has assigned CVE-2026-72459 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 4.13 with commit f1bd904175e8190ce14aedee37e207ab51fe3b30 and fixed in 5.10.261 with commit b14fbacad77d64594228983ec20d61a224f3f491
	Issue introduced in 4.13 with commit f1bd904175e8190ce14aedee37e207ab51fe3b30 and fixed in 5.15.212 with commit b5a9da5d36162d34db0f36abb15420e295176793
	Issue introduced in 4.13 with commit f1bd904175e8190ce14aedee37e207ab51fe3b30 and fixed in 6.1.178 with commit 7cb69e109610bba500e1ecb870f7988a4717208a
	Issue introduced in 4.13 with commit f1bd904175e8190ce14aedee37e207ab51fe3b30 and fixed in 6.6.145 with commit cc2192899d502e3321e60cf1e91421e7309d089c
	Issue introduced in 4.13 with commit f1bd904175e8190ce14aedee37e207ab51fe3b30 and fixed in 6.12.97 with commit bf310b044e85d4de670c94295c5d8e4c5bc5e7bc
	Issue introduced in 4.13 with commit f1bd904175e8190ce14aedee37e207ab51fe3b30 and fixed in 6.18.40 with commit ae02e603c0b39b29f3ce6fe3efe01b286af1a2a4
	Issue introduced in 4.13 with commit f1bd904175e8190ce14aedee37e207ab51fe3b30 and fixed in 7.1.5 with commit 6d91479174240f39e9edea250d95fa08c678a207
	Issue introduced in 4.13 with commit f1bd904175e8190ce14aedee37e207ab51fe3b30 and fixed in 7.2-rc1 with commit 654fe7505dc6889724d4094fa64f89991afabfc3

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-72459
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	security/apparmor/label.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/b14fbacad77d64594228983ec20d61a224f3f491
	https://git.kernel.org/stable/c/b5a9da5d36162d34db0f36abb15420e295176793
	https://git.kernel.org/stable/c/7cb69e109610bba500e1ecb870f7988a4717208a
	https://git.kernel.org/stable/c/cc2192899d502e3321e60cf1e91421e7309d089c
	https://git.kernel.org/stable/c/bf310b044e85d4de670c94295c5d8e4c5bc5e7bc
	https://git.kernel.org/stable/c/ae02e603c0b39b29f3ce6fe3efe01b286af1a2a4
	https://git.kernel.org/stable/c/6d91479174240f39e9edea250d95fa08c678a207
	https://git.kernel.org/stable/c/654fe7505dc6889724d4094fa64f89991afabfc3

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-08-15  6:31 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-15  6:08 CVE-2026-72459: apparmor: aa_label_alloc use aa_label_free on alloc failure Greg Kroah-Hartman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.