In the Linux kernel, the following vulnerability has been resolved:
apparmor: Fix memleak in alloc_ns()
After changes in commit a1bd627b46d1 ("apparmor: share profile name on replacement"), the hname member of struct aa_policy is not valid slab object, but a subset of that, it can not be freed by kfree_sensitive(), use aa_policy_destroy() to fix it.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Dec 31, 2025 | Dec 31, 2025 |
| Huawei Euleros 2_0_sp13 | — | Upgrade kernel-abi-stablelistsUpgrade kernel-tools-libsUpgrade kernel-toolsUpgrade kernelUpgrade bpftoolUpgrade python3-perf | Mar 10, 2026 | Mar 10, 2026 |
| Ubuntu | — | Upgrade linux-aws-5.15Upgrade linux-lowlatencyUpgrade linux-nvidia-tegra-5.15Upgrade linux-riscv-5.15Upgrade linux-intel-iotgUpgrade linux-raspiUpgrade linux-gkeUpgrade linux-oracle-5.15Upgrade linux-lowlatency-hwe-5.15Upgrade linuxUpgrade linux-nvidiaUpgrade linux-realtimeUpgrade linux-oracleUpgrade linux-intel-iot-realtimeUpgrade linux-kvmUpgrade linux-gcp-5.15Upgrade linux-azureUpgrade linux-ibmUpgrade linux-gkeopUpgrade linux-hwe-5.15Upgrade linux-gcpUpgrade linux-bluefieldUpgrade linux-azure-5.15Upgrade linux-awsUpgrade linux-intel-iotg-5.15 | Jan 6, 2026 | Jan 2, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Dec 30, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub