diff --git a/security/apparmor/capability.c b/security/apparmor/capability.c index 7c0f66f1b297..c4a4adc3c29d 100644 --- a/security/apparmor/capability.c +++ b/security/apparmor/capability.c @@ -97,6 +97,8 @@ static int audit_caps(struct apparmor_audit_data *ad, struct aa_profile *profile return error; } else { aa_put_profile(ent->profile); + if (profile != ent->profile) + cap_clear(ent->caps); ent->profile = aa_get_profile(profile); cap_raise(ent->caps, cap); }