logo

New Ubuntu Linux security bypasses require manual mitigations

ID: 8006ece7-8353-5bf5-832f-7e736942fe80

STIX ID: report--8006ece7-8353-5bf5-832f-7e736942fe80

Feed Name: Bleeping Computer

Threat Score
55/100

Date Published: 2025-03-28

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Qualys disclosed three bypasses of Ubuntu's AppArmor unprivileged user namespace restrictions affecting Ubuntu 23.10 and 24.04; the techniques (aa-exec, busybox, and LD_PRELOAD injection) let local unprivileged users create user namespaces with full administrative capabilities and can be chained with kernel vulnerabilities to escalate privileges. Canonical acknowledged the findings, plans AppArmor hardenings, and recommended mitigations such as kernel and profile configuration changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.