logo

CrackArmor Flaws Expose Linux Systems to Privilege Escalation

ID: 28f1f496-5083-50d7-87f0-f4d8c459e0f4

STIX ID: report--28f1f496-5083-50d7-87f0-f4d8c459e0f4

Feed Name: Infosecurity Magazine (News)

Threat Score
78/100

Date Published: 2026-03-16

Date Updated: 2026-04-22

...
...

Qualys Threat Research Unit disclosed nine AppArmor vulnerabilities dubbed "CrackArmor" in the Linux kernel (since 4.11) that allow unprivileged local users to bypass AppArmor profiles, escalate to root, crash kernels (stack exhaustion), cause DoS by loading malicious profiles, and potentially leak kernel memory. Because AppArmor is enabled by default in major distributions (Ubuntu, Debian, SUSE), an estimated 12.6 million enterprise Linux systems are potentially exposed; researchers created PoC exploits (not publicly released) and recommend immediate kernel updates, environment scanning, and monitoring of AppArmor profile directories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.