Description
In the Linux kernel, the following vulnerability has been resolved:

apparmor: aa_label_alloc use aa_label_free on alloc failure

aa_label_alloc() allocates a secid before allocating or taking the label
proxy. If the later proxy step fails, the error path only freed the label
memory, leaking any resources initialized by aa_label_init().

Use aa_label_free() on the failure path so partially initialized labels
release their secid and other label resources before the backing memory is
freed.
Published: 2026-08-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

aa_label_alloc precedes the creation of a label proxy by allocating a security identifier (secid). If the subsequent proxy allocation fails, the error path frees only the memory associated with the label while leaving the secid and other initialized resources unresolved. This causes a kernel‑level resource leak that can grow with repeated failures, potentially exhausting kernel resources and destabilizing the system.

Affected Systems

The flaw exists in all Linux kernel versions that use the AppArmor subsystem and that have not yet incorporated the fix joined to mainline. Distribution kernels that have not received the corresponding update, regardless of distro, are at risk.

Risk and Exploitability

The CVSS score is 7.8, and the EPSS score is < 1%, indicating a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. To exploit the issue an attacker must trigger aa_label_alloc failures, which implies executing code in kernel context and therefore typically requires privileged access; this is an inference drawn from the kernel‑level nature of the code. If repeated failures are induced, the resource leak could culminate in a kernel crash or denial of service. No public exploit has been reported, but the combination of a kernel‑level leak and lack of publicly documented mitigation suggests that proactive patching is prudent.

Generated by OpenCVE AI on August 22, 2026 at 06:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the most recent kernel update that includes the aa_label_alloc fix, correcting the resource (CWE-772) leak.
  • Reboot the system to ensure the updated kernel is active.
  • Enable automatic security updates or monitor distribution advisories to receive timely notifications of kernel patches addressing CWE-772 vulnerabilities.

Generated by OpenCVE AI on August 22, 2026 at 06:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Wed, 19 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 17 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-401

Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: apparmor: aa_label_alloc use aa_label_free on alloc failure aa_label_alloc() allocates a secid before allocating or taking the label proxy. If the later proxy step fails, the error path only freed the label memory, leaking any resources initialized by aa_label_init(). Use aa_label_free() on the failure path so partially initialized labels release their secid and other label resources before the backing memory is freed.
Title apparmor: aa_label_alloc use aa_label_free on alloc failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:44:25.217Z

Reserved: 2026-08-09T03:40:39.932Z

Link: CVE-2026-72459

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:19.877

Modified: 2026-08-17T06:19:13.530

Link: CVE-2026-72459

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72459 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T06:45:04Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime