CVE-2026-72459

Summary

In the Linux kernel, the following vulnerability has been resolved:

apparmor: aa_label_alloc use aa_label_free on alloc failure

aa_label_alloc() allocates a secid before allocating or taking the label proxy. If the later proxy step fails, the error path only freed the label memory, leaking any resources initialized by aa_label_init().

Use aa_label_free() on the failure path so partially initialized labels release their secid and other label resources before the backing memory is freed.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxf1bd904175e8190ce14aedee37e207ab51fe3b30 < b14fbacad77d64594228983ec20d61a224f3f491affected
LinuxLinuxf1bd904175e8190ce14aedee37e207ab51fe3b30 < b5a9da5d36162d34db0f36abb15420e295176793affected
LinuxLinuxf1bd904175e8190ce14aedee37e207ab51fe3b30 < 7cb69e109610bba500e1ecb870f7988a4717208aaffected
LinuxLinuxf1bd904175e8190ce14aedee37e207ab51fe3b30 < cc2192899d502e3321e60cf1e91421e7309d089caffected
LinuxLinuxf1bd904175e8190ce14aedee37e207ab51fe3b30 < bf310b044e85d4de670c94295c5d8e4c5bc5e7bcaffected
LinuxLinuxf1bd904175e8190ce14aedee37e207ab51fe3b30 < ae02e603c0b39b29f3ce6fe3efe01b286af1a2a4affected
LinuxLinuxf1bd904175e8190ce14aedee37e207ab51fe3b30 < 6d91479174240f39e9edea250d95fa08c678a207affected
LinuxLinuxf1bd904175e8190ce14aedee37e207ab51fe3b30 < 654fe7505dc6889724d4094fa64f89991afabfc3affected
LinuxLinux4.13affected
LinuxLinux0 < 4.13unaffected
LinuxLinux5.10.261 <= 5.10.*unaffected
LinuxLinux5.15.212 <= 5.15.*unaffected
LinuxLinux6.1.178 <= 6.1.*unaffected
LinuxLinux6.6.145 <= 6.6.*unaffected
LinuxLinux6.12.97 <= 6.12.*unaffected
LinuxLinux6.18.40 <= 6.18.*unaffected
LinuxLinux7.1.5 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References