Linux AppArmor Bugs Allow Root Escalation and Container Bypasses
Mar 13, 2026 // 14:33 - Lina Schonbein


Researchers at Qualys Threat Research Unit (TRU) have disclosed nine vulnerabilities in the Linux AppArmor security module, collectively dubbed “CrackArmor”. These flaws allow unprivileged local users to bypass kernel protections, escalate to root privileges, and break container isolation.

Key Details of CrackArmor

  • Vulnerability Type: Confused deputy flaws that exploit how AppArmor handles security profiles via pseudo-files (e.g., /sys/kernel/security/apparmor/.load and .replace).
  • Affected Systems: Estimated 12.6 million enterprise Linux instances worldwide.
  • Impacted Distributions: Major distributions using AppArmor as a default Mandatory Access Control (MAC) mechanism, including Ubuntu, Debian, and SUSE.
  • Longevity: The vulnerabilities have existed in the Linux kernel since 2017 (starting with version v4.11).
  • CVE Status: As of March 13, 2026, no CVE identifiers have been assigned. This is due to the upstream Linux kernel team’s policy of issuing IDs only after fixes have been in stable releases for one to two weeks.

Attack Mechanisms and Impact

  • Root Escalation: Attackers can abuse privileged tools like Sudo or Postfix to manipulate AppArmor profiles, leading to local privilege escalation (LPE).
  • Container Escape: By bypassing user-namespace restrictions, attackers can undermine container isolation and execute arbitrary code within the host kernel.
  • Additional Risks: The flaws also enable denial-of-service (DoS) via stack exhaustion and Kernel Address Space Layout Randomization (KASLR) bypasses via out-of-bounds reads. 

Required Actions

Immediate kernel patching is required to mitigate these vulnerabilities.

  • Ubuntu: Updates are currently rolling out for all affected releases (back to 20.04 LTS for certain components).
  • Debian: Fixes have been released for the “bookworm” distribution in version 6.1.164-1.
  • Enterprise Environments: Organizations in cloud computing, finance, and healthcare are urged to prioritize patching internet-facing assets.

#allow  #and  #apparmor  #bugs  #bypasses  #container  #escalation  #linux  #news  #root   —   News