We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2022-50077

apparmor: fix reference count leak in aa_pivotroot()



Description

In the Linux kernel, the following vulnerability has been resolved: apparmor: fix reference count leak in aa_pivotroot() The aa_pivotroot() function has a reference counting bug in a specific path. When aa_replace_current_label() returns on success, the function forgets to decrement the reference count of “target”, which is increased earlier by build_pivotroot(), causing a reference leak. Fix it by decreasing the refcount of “target” in that path.

Reserved 2025-06-18 | Published 2025-06-18 | Updated 2025-06-18 | Assigner Linux

Product status

Default status
unaffected

2ea3ffb7782a84da33a8382f13ebd016da50079b before d53194707d2a1851be027cd74266b96ceff799d3
affected

2ea3ffb7782a84da33a8382f13ebd016da50079b before f4d5c7796571624e3f380b447ada52834270a287
affected

2ea3ffb7782a84da33a8382f13ebd016da50079b before ef6fb6f0d0d8440595b45a7e53c6162c737177f4
affected

2ea3ffb7782a84da33a8382f13ebd016da50079b before 2ceeb3296e9dde1d5772348046affcefdea605e2
affected

2ea3ffb7782a84da33a8382f13ebd016da50079b before 64103ea357734b82384c925cba4758fdb909be0c
affected

2ea3ffb7782a84da33a8382f13ebd016da50079b before 3ca40ad7afae144169a43988ef1a3f16182faf0a
affected

2ea3ffb7782a84da33a8382f13ebd016da50079b before 11c3627ec6b56c1525013f336f41b79a983b4d46
affected

Default status
affected

4.14
affected

Any version before 4.14
unaffected

4.14.291
unaffected

4.19.256
unaffected

5.4.211
unaffected

5.10.138
unaffected

5.15.63
unaffected

5.19.4
unaffected

6.0
unaffected

References

git.kernel.org/...c/d53194707d2a1851be027cd74266b96ceff799d3

git.kernel.org/...c/f4d5c7796571624e3f380b447ada52834270a287

git.kernel.org/...c/ef6fb6f0d0d8440595b45a7e53c6162c737177f4

git.kernel.org/...c/2ceeb3296e9dde1d5772348046affcefdea605e2

git.kernel.org/...c/64103ea357734b82384c925cba4758fdb909be0c

git.kernel.org/...c/3ca40ad7afae144169a43988ef1a3f16182faf0a

git.kernel.org/...c/11c3627ec6b56c1525013f336f41b79a983b4d46

cve.org (CVE-2022-50077)

nvd.nist.gov (CVE-2022-50077)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2022-50077

Support options

Helpdesk Chat, Email, Knowledgebase