« Volver al listado

CVE-2022-50077

Estado: AnalizadaMedia (5.5)—

In the Linux kernel, the following vulnerability has been resolved:

apparmor: fix reference count leak in aa_pivotroot()

The aa_pivotroot() function has a reference counting bug in a specific path. When aa_replace_current_label() returns on success, the function forgets to decrement the reference count of “target”, which is increased earlier by build_pivotroot(), causing a reference leak.

Fix it by decreasing the refcount of “target” in that path.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-50077",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2ea3ffb7782a84da33a8382f13ebd016da50079b",
              "lessThan": "d53194707d2a1851be027cd74266b96ceff799d3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2ea3ffb7782a84da33a8382f13ebd016da50079b",
              "lessThan": "f4d5c7796571624e3f380b447ada52834270a287",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2ea3ffb7782a84da33a8382f13ebd016da50079b",
              "lessThan": "ef6fb6f0d0d8440595b45a7e53c6162c737177f4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2ea3ffb7782a84da33a8382f13ebd016da50079b",
              "lessThan": "2ceeb3296e9dde1d5772348046affcefdea605e2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2ea3ffb7782a84da33a8382f13ebd016da50079b",
              "lessThan": "64103ea357734b82384c925cba4758fdb909be0c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2ea3ffb7782a84da33a8382f13ebd016da50079b",
              "lessThan": "3ca40ad7afae144169a43988ef1a3f16182faf0a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "2ea3ffb7782a84da33a8382f13ebd016da50079b",
              "lessThan": "11c3627ec6b56c1525013f336f41b79a983b4d46",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "security/apparmor/mount.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.14"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.14",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "4.14.291",
              "versionType": "semver",
              "lessThanOrEqual": "4.14.*"
            },
            {
              "status": "unaffected",
              "version": "4.19.256",
              "versionType": "semver",
              "lessThanOrEqual": "4.19.*"
            },
            {
              "status": "unaffected",
              "version": "5.4.211",
              "versionType": "semver",
              "lessThanOrEqual": "5.4.*"
            },
            {
              "status": "unaffected",
              "version": "5.10.138",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.63",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "5.19.4",
              "versionType": "semver",
              "lessThanOrEqual": "5.19.*"
            },
            {
              "status": "unaffected",
              "version": "6.0",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "security/apparmor/mount.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-06-18T11:15:36.627",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/11c3627ec6b56c1525013f336f41b79a983b4d46",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2ceeb3296e9dde1d5772348046affcefdea605e2",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/3ca40ad7afae144169a43988ef1a3f16182faf0a",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/64103ea357734b82384c925cba4758fdb909be0c",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d53194707d2a1851be027cd74266b96ceff799d3",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ef6fb6f0d0d8440595b45a7e53c6162c737177f4",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f4d5c7796571624e3f380b447ada52834270a287",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: fix reference count leak in aa_pivotroot()\n\nThe aa_pivotroot() function has a reference counting bug in a specific\npath. When aa_replace_current_label() returns on success, the function\nforgets to decrement the reference count of “target”, which is\nincreased earlier by build_pivotroot(), causing a reference leak.\n\nFix it by decreasing the refcount of “target” in that path."
    },
    {
      "lang": "es",
      "value": "En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: apparmor: se corrige una fuga de referencias en aa_pivotroot(). La función aa_pivotroot() presenta un error de conteo de referencias en una ruta específica. Cuando aa_replace_current_label() retorna con éxito, la función olvida decrementar el conteo de referencias de \"target\", que se incrementa previamente mediante build_pivotroot(), lo que provoca una fuga de referencias. Para solucionarlo, reduzca el conteo de referencias de \"target\" en esa ruta."
    }
  ],
  "lastModified": "2026-06-17T05:22:42.770",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6CA67D14-5A27-41CC-9569-F5C7E514E52B",
              "versionEndExcluding": "4.14.291",
              "versionStartIncluding": "4.14.1"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6C47CDE3-B039-4AE5-B8E4-1DC820E473FF",
              "versionEndExcluding": "4.19.256",
              "versionStartIncluding": "4.15"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B1C63D19-C08C-4308-A848-B2523C9275BD",
              "versionEndExcluding": "5.4.211",
              "versionStartIncluding": "4.20"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "445ACC04-A2BA-4176-B4C9-CA4AA59096D2",
              "versionEndExcluding": "5.10.138",
              "versionStartIncluding": "5.5"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D5744A03-DA40-4A78-9063-13179361DC6D",
              "versionEndExcluding": "5.15.63",
              "versionStartIncluding": "5.11"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0E669300-DA42-4ACD-86D8-68BE5F29FB88",
              "versionEndExcluding": "5.19.4",
              "versionStartIncluding": "5.16"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:4.14:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7875AA30-1F6F-470C-A52D-ECBD6663CEC5"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:4.14:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B483DA9A-D449-48DE-9CA2-CEA23FD0B202"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:4.14:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DEF29F06-4FF7-4FE6-B66D-9D758B182CF3"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:4.14:rc4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "17941A19-6A3D-477F-BC6A-972D7F815FDD"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:4.14:rc5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4C9B8FA6-754F-42F5-98BC-410AF7DB9F4C"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:4.14:rc6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EC8F8565-B401-4F3C-B423-51F371DCB908"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:4.14:rc7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C834B5F2-810F-4291-8E1F-1B32635E08F3"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:4.14:rc8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BB4A96BC-72CC-4EF1-916C-9ED7177C196E"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}