logo

CrackArmor: Critical AppArmor Flaws Enable Local Privilege Escalation to Root

ID: 8ef9ebd2-e7bc-5ce7-81f3-b994e9fd7a47

STIX ID: report--8ef9ebd2-e7bc-5ce7-81f3-b994e9fd7a47

Feed Name: Qualys Blog

Threat Score
85/100

Date Published: 2026-03-12

Date Updated: 2026-04-28

Author: Saeed Abbasi

...
...

**CrackArmor (AppArmor) — Executive Summary:** Qualys TRU discloses nine AppArmor implementation vulnerabilities present since Linux kernel v4.11 that allow unprivileged actors to manipulate pseudo-files to load/replace/remove profiles, bypass user‑namespace restrictions, cause kernel stack exhaustion (panic/DoS), disclose memory (KASLR bypass), break container isolation, and achieve local privilege escalation to root; the advisory includes PoCs (withheld publicly), vendor coordination, QIDs for detection, and an urgent recommendation to apply kernel patches immediately across Ubuntu, Debian, SUSE and affected deployments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.