CVE-2026-72461

Source
https://cve.org/CVERecord?id=CVE-2026-72461
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72461.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72461
Downstream
Published
2026-08-15T05:57:06.042Z
Modified
2026-08-18T03:56:26.355585851Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
apparmor: fix refcount leak when updating the sk_ctx
Details

In the Linux kernel, the following vulnerability has been resolved:

apparmor: fix refcount leak when updating the sk_ctx

Currently updateskctx() transfers the plabel reference, unfortunately it is also unconditionally put in the caller. Ideally we would make the caller conditionally put the reference based on whether it was transferred but for now just fix the bug by getting a reference.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72461.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
88fec3526e84123997ecebd6bb6778eb4ce779b7
Fixed
045dbe89ac31709abd73390d0805d52fece7ef39
Fixed
b8642f1478982a97ca2eb59f70f631a9de42ae11
Fixed
6d25e7b47616cb2db43351210929c8f19dc305a3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72461.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.17.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72461.json"