CVE-2026-72460

Source
https://cve.org/CVERecord?id=CVE-2026-72460
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72460.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72460
Downstream
Published
2026-08-15T05:57:05.404Z
Modified
2026-08-16T03:48:42.679114741Z
Summary
apparmor: check label build before no_new_privs test
Details

In the Linux kernel, the following vulnerability has been resolved:

apparmor: check label build before nonewprivs test

aachangeprofile() builds a replacement label with fnlabelbuildinscope() before the nonewprivs subset check. The build helper can fail and return NULL or an ERRPTR, but the result was passed to aalabelisunconfinedsubset() before the existing ISERRORNULL() check.

Reuse the existing target-label build failure handling immediately after the build. This preserves the current audit handling while preventing the subset helper from dereferencing an invalid label.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72460.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
e00b02bb6ac2a1893227ce8014b649028d6425d2
Fixed
a29f06db44b4c94597ded58f639eed3e21781ac3
Fixed
cfc224866530a6842b6c2d2d30ef6a9b0e64bb9c
Fixed
31cb109db5e6322ed22304fd5c0dedbaa438d6d3
Fixed
b7c45c05a396a017c49ac7949de240a0dfc0ac4e
Fixed
d84bb195d208adbf77f012ca2a96e11163f6def1
Fixed
d82160132345688a09cbaa648cfdd16bb32e8ea2
Fixed
ec926b2a351eeeb31e6c9aee02e0c32f94b5588f
Fixed
a58cafd38b46fb1a2220e2fbbcfe291ea75fa147

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72460.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.13.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72460.json"