CVE-2022-50074

medium

Description

In the Linux kernel, the following vulnerability has been resolved: apparmor: Fix memleak in aa_simple_write_to_buffer() When copy_from_user failed, the memory is freed by kvfree. however the management struct and data blob are allocated independently, so only kvfree(data) cause a memleak issue here. Use aa_put_loaddata(data) to fix this issue.

References

https://git.kernel.org/stable/c/bf7ebebce2c25071c719fd8a2f1307e0c243c2d7

https://git.kernel.org/stable/c/8aab4295582eb397a125d2788b829fa62b88dbf7

https://git.kernel.org/stable/c/7db182a2ebeefded86fea542fcc5d6a68bb77f58

https://git.kernel.org/stable/c/6583edbf459de2e06b9759f264c0ae27e452b97a

https://git.kernel.org/stable/c/6500eb3a48ac221051b1791818a1ac74744ef617

https://git.kernel.org/stable/c/417ea9fe972d2654a268ad66e89c8fcae67017c3

Details

Source: Mitre, NVD

Published: 2025-06-18

Updated: 2025-06-18

Risk Information

CVSS v2

Base Score: 2.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:N

Severity: Low

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00024