CrackArmor Flaws Expose Linux Systems to Privilege Escalation
ID: 28f1f496-5083-50d7-87f0-f4d8c459e0f4
STIX ID: report--28f1f496-5083-50d7-87f0-f4d8c459e0f4
Feed Name: Infosecurity Magazine (News)
Qualys Threat Research Unit disclosed nine AppArmor vulnerabilities dubbed "CrackArmor" in the Linux kernel (since 4.11) that allow unprivileged local users to bypass AppArmor profiles, escalate to root, crash kernels (stack exhaustion), cause DoS by loading malicious profiles, and potentially leak kernel memory. Because AppArmor is enabled by default in major distributions (Ubuntu, Debian, SUSE), an estimated 12.6 million enterprise Linux systems are potentially exposed; researchers created PoC exploits (not publicly released) and recommend immediate kernel updates, environment scanning, and monitoring of AppArmor profile directories.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
