CVE-2026-72459

Source
https://cve.org/CVERecord?id=CVE-2026-72459
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72459.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72459
Downstream
Published
2026-08-15T05:57:04.794Z
Modified
2026-08-18T03:56:56.460718859Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
apparmor: aa_label_alloc use aa_label_free on alloc failure
Details

In the Linux kernel, the following vulnerability has been resolved:

apparmor: aalabelalloc use aalabelfree on alloc failure

aalabelalloc() allocates a secid before allocating or taking the label proxy. If the later proxy step fails, the error path only freed the label memory, leaking any resources initialized by aalabelinit().

Use aalabelfree() on the failure path so partially initialized labels release their secid and other label resources before the backing memory is freed.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72459.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f1bd904175e8190ce14aedee37e207ab51fe3b30
Fixed
b14fbacad77d64594228983ec20d61a224f3f491
Fixed
b5a9da5d36162d34db0f36abb15420e295176793
Fixed
7cb69e109610bba500e1ecb870f7988a4717208a
Fixed
cc2192899d502e3321e60cf1e91421e7309d089c
Fixed
bf310b044e85d4de670c94295c5d8e4c5bc5e7bc
Fixed
ae02e603c0b39b29f3ce6fe3efe01b286af1a2a4
Fixed
6d91479174240f39e9edea250d95fa08c678a207
Fixed
654fe7505dc6889724d4094fa64f89991afabfc3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72459.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.13.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72459.json"