CVE-2022-50860: Linux
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: apparmor: Fix memleak in alloc_ns() After changes in commit a1bd627b46d1 ("apparmor: share profile name on replacement"), the hname member of struct aa_policy is not valid slab object, but a subset of that, it can not be freed by kfree_sensitive(), use aa_policy_destroy() to fix it.
Affected products
- Linux Linux: from 4.13, before 5.10.163 (fixed in 5.10.163); from 5.11, before 5.15.86 (fixed in 5.15.86); from 5.16, before 6.0.16 (fixed in 6.0.16); from 6.1, before 6.1.2 (fixed in 6.1.2)
Published 2025-12-30. Last modified 2026-08-04.