CVE-2022-50860

Source
https://cve.org/CVERecord?id=CVE-2022-50860
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-50860.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-50860
Downstream
Related
Published
2025-12-30T12:15:33.859Z
Modified
2026-03-20T12:22:39.076024Z
Summary
apparmor: Fix memleak in alloc_ns()
Details

In the Linux kernel, the following vulnerability has been resolved:

apparmor: Fix memleak in alloc_ns()

After changes in commit a1bd627b46d1 ("apparmor: share profile name on replacement"), the hname member of struct aapolicy is not valid slab object, but a subset of that, it can not be freed by kfreesensitive(), use aapolicydestroy() to fix it.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/50xxx/CVE-2022-50860.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
a1bd627b46d169268a0ee5960899fb5be960a317
Fixed
9a32aa87a25d800b2c6f47bc2749a7bfd9a486f3
Fixed
5f509fa740b17307f0cba412485072f632d5af36
Fixed
0250cf8d37bb5201a117177afd24dc73a1c81657
Fixed
12695b4b76d437b9c0182a6f7dfb2248013a9daf
Fixed
e9e6fa49dbab6d84c676666f3fe7d360497fd65b

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-50860.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.13.0
Fixed
5.10.163
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.86
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.0.16
Type
ECOSYSTEM
Events
Introduced
6.1.0
Fixed
6.1.2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-50860.json"