New Ubuntu Security Bypasses Allow Attackers to Exploit Kernel Vulnerabilities
ID: 5c581aaf-6bf4-54f9-aa0d-d4f1f12992a8
STIX ID: report--5c581aaf-6bf4-54f9-aa0d-d4f1f12992a8
Feed Name: cybersecurityNews.com
Qualys TRU disclosed three AppArmor bypasses on Ubuntu 23.10 and 24.04 LTS — via aa-exec, Busybox, and LD_PRELOAD — that permit unprivileged users to create unrestricted namespaces. While not directly granting full system control, these bypasses facilitate local privilege escalation when chained with kernel vulnerabilities; recommended mitigations include enabling kernel.apparmor_restrict_unprivileged_unconfined, hardening or disabling permissive AppArmor profiles (Busybox, Nautilus), and tightening bwrap/Flatpak profiles.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
