CVE-2022-50077
published 2025-06-18CVE-2022-50077: In the Linux kernel, the following vulnerability has been resolved: apparmor: fix reference count leak in aa_pivotroot() The aa_pivotroot() function has a…
PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.16%
5.7th percentile
In the Linux kernel, the following vulnerability has been resolved:
apparmor: fix reference count leak in aa_pivotroot()
The aa_pivotroot() function has a reference counting bug in a specific
path. When aa_replace_current_label() returns on success, the function
forgets to decrement the reference count of “target”, which is
increased earlier by build_pivotroot(), causing a reference leak.
Fix it by decreasing the refcount of “target” in that path.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.0.2-1 (bookworm) | linux 6.0.2-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= 2ea3ffb7782a84da33a8382f13ebd016da50079b < d53194707d2a1851be027cd74266b96ceff799d3 | d53194707d2a1851be027cd74266b96ceff799d3 |
| linux | linux | >= 2ea3ffb7782a84da33a8382f13ebd016da50079b < f4d5c7796571624e3f380b447ada52834270a287 | f4d5c7796571624e3f380b447ada52834270a287 |
| linux | linux | >= 2ea3ffb7782a84da33a8382f13ebd016da50079b < ef6fb6f0d0d8440595b45a7e53c6162c737177f4 | ef6fb6f0d0d8440595b45a7e53c6162c737177f4 |
| linux | linux | >= 2ea3ffb7782a84da33a8382f13ebd016da50079b < 2ceeb3296e9dde1d5772348046affcefdea605e2 | 2ceeb3296e9dde1d5772348046affcefdea605e2 |
| linux | linux | >= 2ea3ffb7782a84da33a8382f13ebd016da50079b < 64103ea357734b82384c925cba4758fdb909be0c | 64103ea357734b82384c925cba4758fdb909be0c |
| linux | linux | >= 2ea3ffb7782a84da33a8382f13ebd016da50079b < 3ca40ad7afae144169a43988ef1a3f16182faf0a | 3ca40ad7afae144169a43988ef1a3f16182faf0a |
| linux | linux | >= 2ea3ffb7782a84da33a8382f13ebd016da50079b < 11c3627ec6b56c1525013f336f41b79a983b4d46 | 11c3627ec6b56c1525013f336f41b79a983b4d46 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.10.140-1 | 5.10.140-1 |
| linux | linux_kernel | >= 0 < 6.0.2-1 | 6.0.2-1 |
| linux | linux_kernel | >= 0 < 6.0.2-1 | 6.0.2-1 |
| linux | linux_kernel | >= 0 < 6.0.2-1 | 6.0.2-1 |
| linux | linux_kernel | >= 4.14.1 < 4.14.291 | 4.14.291 |
| linux | linux_kernel | >= 4.15 < 4.19.256 | 4.19.256 |
| linux | linux_kernel | >= 4.20 < 5.4.211 | 5.4.211 |
| linux | linux_kernel | >= 5.11 < 5.15.63 | 5.15.63 |
| linux | linux_kernel | >= 5.16 < 5.19.4 | 5.19.4 |
| linux | linux_kernel | >= 5.5 < 5.10.138 | 5.10.138 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: apparmor: fix reference count leak in aa_pivotroot()
vendor_redhat·2025-06-18·CVSS 5.5
CVE-2022-50077 [MEDIUM] kernel: apparmor: fix reference count leak in aa_pivotroot()
kernel: apparmor: fix reference count leak in aa_pivotroot()
In the Linux kernel, the following vulnerability has been resolved:
apparmor: fix reference count leak in aa_pivotroot()
The aa_pivotroot() function has a reference counting bug in a specific
path. When aa_replace_current_label() returns on success, the function
forgets to decrement the reference count of “target”, which is
increased earlier by build_pivotroot(), causing a reference leak.
Fix it by decreasing the refcount of “target” in that path.
Package: kernel (Red Hat Enterprise Linux 10) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise L
Debian
CVE-2022-50077: linux - In the Linux kernel, the following vulnerability has been resolved: apparmor: f...
vendor_debian·2022·CVSS 5.5
CVE-2022-50077 [MEDIUM] CVE-2022-50077: linux - In the Linux kernel, the following vulnerability has been resolved: apparmor: f...
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix reference count leak in aa_pivotroot() The aa_pivotroot() function has a reference counting bug in a specific path. When aa_replace_current_label() returns on success, the function forgets to decrement the reference count of “target”, which is increased earlier by build_pivotroot(), causing a reference leak. Fix it by decreasing the refcount of “target” in that path.
Scope: local
bookworm: resolved (fixed in 6.0.2-1)
bullseye: resolved (fixed in 5.10.140-1)
forky: resolved (fixed in 6.0.2-1)
sid: resolved (fixed in 6.0.2-1)
trixie: resolved (fixed in 6.0.2-1)
GHSA
GHSA-6q7v-49c4-hj5m: In the Linux kernel, the following vulnerability has been resolved:
apparmor: fix reference count leak in aa_pivotroot()
The aa_pivotroot() function
ghsa_unreviewed·2025-06-18
CVE-2022-50077 [MEDIUM] GHSA-6q7v-49c4-hj5m: In the Linux kernel, the following vulnerability has been resolved:
apparmor: fix reference count leak in aa_pivotroot()
The aa_pivotroot() function
In the Linux kernel, the following vulnerability has been resolved:
apparmor: fix reference count leak in aa_pivotroot()
The aa_pivotroot() function has a reference counting bug in a specific
path. When aa_replace_current_label() returns on success, the function
forgets to decrement the reference count of “target”, which is
increased earlier by build_pivotroot(), causing a reference leak.
Fix it by decreasing the refcount of “target” in that path.
OSV
CVE-2022-50077: In the Linux kernel, the following vulnerability has been resolved: apparmor: fix reference count leak in aa_pivotroot() The aa_pivotroot() function h
osv·2025-06-18·CVSS 5.5
CVE-2022-50077 [MEDIUM] CVE-2022-50077: In the Linux kernel, the following vulnerability has been resolved: apparmor: fix reference count leak in aa_pivotroot() The aa_pivotroot() function h
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix reference count leak in aa_pivotroot() The aa_pivotroot() function has a reference counting bug in a specific path. When aa_replace_current_label() returns on success, the function forgets to decrement the reference count of “target”, which is increased earlier by build_pivotroot(), causing a reference leak. Fix it by decreasing the refcount of “target” in that path.
No detection rules found.
No public exploits indexed.
https://git.kernel.org/stable/c/11c3627ec6b56c1525013f336f41b79a983b4d46https://git.kernel.org/stable/c/2ceeb3296e9dde1d5772348046affcefdea605e2https://git.kernel.org/stable/c/3ca40ad7afae144169a43988ef1a3f16182faf0ahttps://git.kernel.org/stable/c/64103ea357734b82384c925cba4758fdb909be0chttps://git.kernel.org/stable/c/d53194707d2a1851be027cd74266b96ceff799d3https://git.kernel.org/stable/c/ef6fb6f0d0d8440595b45a7e53c6162c737177f4https://git.kernel.org/stable/c/f4d5c7796571624e3f380b447ada52834270a287
2025-06-18
Published