logo

Nine CrackArmor Flaws in Linux AppArmor Enable Root Escalation, Bypass Container Isolation

ID: 0d0282d4-3e65-53a8-9cb1-a6b869c55142

STIX ID: report--0d0282d4-3e65-53a8-9cb1-a6b869c55142

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-03-13

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

## Executive Summary Qualys TRU disclosed nine AppArmor 'confused deputy' vulnerabilities called "CrackArmor" affecting Linux kernels since 4.11 that allow unprivileged users to manipulate security profiles, bypass user-namespace restrictions, achieve local privilege escalation to root, subvert container isolation, perform denial-of-service, and leak KASLR. The flaws impact distributions that enable AppArmor by default (e.g., Ubuntu, Debian, SUSE); PoC exploits are being withheld and immediate kernel patching is recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.