-

CVE-2026-72456

apparmor: release exe file resources on path failure

In the Linux kernel, the following vulnerability has been resolved:

apparmor: release exe file resources on path failure

get_current_exe_path() takes both an exe_file reference and a path
reference before resolving the path name. If aa_path_name() failed, it
returned immediately and leaked both references.

Route the failure through the common cleanup path so fput() and path_put()
always run after the references are acquired.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 8d34e16f7f2b51f880957f2caadaae731ee28867
Version < 393809a05cfb60309ad63ee09138db8296d6b97e
Status affected
Version 8d34e16f7f2b51f880957f2caadaae731ee28867
Version < 7306c41672487a6c28430714be063bc6942c28f2
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 7.0
Status affected
Version 0
Version < 7.0
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.089
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/393809a05cfb60309ad63ee09138db8296d6b97e
https://git.kernel.org/stable/c/7306c41672487a6c28430714be063bc6942c28f2