CVE-2026-72461

Summary

In the Linux kernel, the following vulnerability has been resolved:

apparmor: fix refcount leak when updating the sk_ctx

Currently update_sk_ctx() transfers the plabel reference, unfortunately it is also unconditionally put in the caller. Ideally we would make the caller conditionally put the reference based on whether it was transferred but for now just fix the bug by getting a reference.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux88fec3526e84123997ecebd6bb6778eb4ce779b7 < 045dbe89ac31709abd73390d0805d52fece7ef39affected
LinuxLinux88fec3526e84123997ecebd6bb6778eb4ce779b7 < b8642f1478982a97ca2eb59f70f631a9de42ae11affected
LinuxLinux88fec3526e84123997ecebd6bb6778eb4ce779b7 < 6d25e7b47616cb2db43351210929c8f19dc305a3affected
LinuxLinux6.17affected
LinuxLinux0 < 6.17unaffected
LinuxLinux6.18.40 <= 6.18.*unaffected
LinuxLinux7.1.5 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References