Компания Qualys сообщила о девяти уязвимостях в AppArmor и объединила находки под названием CrackArmor.

https://blog.qualys.com/vulnerabilities-threat-research/2026/03/12/crackarmor-critical-apparmor-flaws-enable-local-privilege-escalation-to-root

Проблема появилась ещё в 2017 году вместе с ядром Linux версии 4.11.

AppArmor входит в ядро Linux и выполняет роль обязательного контроля доступа. Механизм ограничивает возможности отдельных программ, не позволяя приложениям читать чужие файлы, выполнять опасные системные вызовы или получать дополнительные права.

CrackArmor позволяет локальному пользователю без прав root-а манипулировать профилями безопасности через специальные псевдофайлы в каталоге /sys/kernel/security/apparmor/. В результате атакующий способен повысить привилегии до уровня root.

До появления патчей необходимо контролировать изменения в каталоге `/sys/kernel/security/apparmor/`, поскольку подозрительная модификация профилей может указывать на попытку эксплуатации уязвимости.

https://www.securitylab.ru/news/570418.php

#Linux #apparmor #crackarmor #vulnerability

CrackArmor Vulnerability 2026: AppArmor Root Access & Qualys Detection | Qualys

CrackArmor — nine AppArmor flaws enable root access & container escape on 12M+ Linux systems. Qualys TRU discovered & validated. Learn attack paths, impact, and immediate mitigation steps. Patch now.

Qualys

RE: https://piaille.fr/@EvolixNOC/116222120693299885

Une explication en vidéo (en anglais) de cette vilaine faille : https://youtu.be/TRPUpErYeco #CrackArmor

🔴 CrackArmor : 9 failles AppArmor menacent 12,6 millions de serveurs Linux - patchez maintenant

Les chercheurs Qualys révèlent CrackArmor : 9 vulnérabilités AppArmor permettant l'escalade root sur Ubuntu, Debian et SUSE. Correctifs disponibles, redémarrage obligatoire.

Goodtech

AppArmor-Sicherheitslücken erklärt: Was „CrackArmor“ für Linux-Nutzer wirklich bedeutet

**Sicherheitslücken in AppArmor: Warum Linux-Updates jetzt wichtig sind** Neun kritische Schwachstellen in AppArmor (CrackArmor) ermöglichen Rechteausweitung und Container-Escape. Betroffen sind Ubuntu-Systeme – Updates sind dringend nötig.

https://dasnetzundich.de/apparmor-sicherheitsluecken-erklaert-was-crackarmor-fuer-linux-nutzer-wirklich-bedeutet/

AppArmor-Sicherheitslücken erklärt: Was „CrackArmor“ für Linux-Nutzer wirklich bedeutet | Das Netz und ich

**Sicherheitslücken in AppArmor: Warum Linux-Updates jetzt wichtig sind** Neun kritische Schwachstellen in AppArmor (CrackArmor) ermöglichen Rechteausweitung und Container-Escape. Betroffen sind Ubuntu-Systeme – Updates sind dringend nötig.

In the context of releasing updated packages that fix critical vulnerabilities, what does "Will be published imminently" actually mean?

I'm looking at #Canonical (@ubuntu) right now, as some of the packages to mitigate #CrackArmor on Azure have been saying that since, at least, Monday.

Any indication of a concrete date for this to be available?

Ref: https://ubuntu.com/security/vulnerabilities/crackarmor#affected-releases

#Ubuntu #Linux #Security

Achtung CrackArmor: Neue AppArmor Lücken bedrohen Linux Systeme https://fosstopia.de/linux-apparmor-lucken/ #AppArmor #CrackArmor #EnterpriseLinux #Kernel #Linux #LinuxSecurity

#CrackArmor : neuf vulnérabilités ont été découvertes dans #AppArmor remontant au noyau #Linux 4.11 (2017) et pourraient affecter plus de 12,6 millions de systèmes.

https://blog.qualys.com/vulnerabilities-threat-research/2026/03/12/crackarmor-critical-apparmor-flaws-enable-local-privilege-escalation-to-root

CrackArmor Vulnerability 2026: AppArmor Root Access & Qualys Detection | Qualys

CrackArmor — nine AppArmor flaws enable root access & container escape on 12M+ Linux systems. Qualys TRU discovered & validated. Learn attack paths, impact, and immediate mitigation steps. Patch now.

Qualys
Blip blop, I'm a #mastobot.
Here is a summary (in beta) of the latest posts in #programmingAtKukei https://masto.kukei.eu/browse/programming category:
- **AI coding agents & tools**: CrackArmor Linux vulnerability, Claude Code updates (code review, subagents), Goose AI agent, GitHub Copilot, AI-generated PRs, and debates on AI’s role in open-source (e.g., Redox OS banning LLM-generated code).
- **Security vulnerabilities**: 7-year-old Linux flaw (#CrackArmor) exposing 12.6M systems, Swedish [1/3]
masto.kukei.eu

Mastodon real-time search engine

A 7-year-old Linux flaw dubbed #CrackArmor exposes 12.6 million systems using AppArmor. Researchers found that it can enable root access, container escape, and security bypass. Patch immediately.

Read: https://hackread.com/crackarmor-vulnerability-apparmor-linux-systems/

#Linux #CyberSecurity #AppArmor #Vulnerability

‘CrackArmor’ Vulnerability in AppArmor Impacts 12.6M Linux Systems

Qualys uncovers 'CrackArmor' vulnerabilities in AppArmor that could expose 12.6M Linux systems to root access and container escapes.

Hackread - Cybersecurity News, Data Breaches, AI and More

#CrackArmor: Multiple vulnerabilities in #AppArmor

Blogpost: https://blog.qualys.com/vulnerabilities-threat-research/2026/03/12/crackarmor-critical-apparmor-flaws-enable-local-privilege-escalation-to-root

Advisory: https://cdn2.qualys.com/advisory/2026/03/10/crack-armor.txt

These vulnerabilities allow a local attacker to bypass the security normally provided by AppArmor. Also, in some situations, it allows privilege escalation to root by selectively blocking specific syscalls.

#infosec #cybersecurity #qualys

CrackArmor Vulnerability 2026: AppArmor Root Access & Qualys Detection | Qualys

CrackArmor — nine AppArmor flaws enable root access & container escape on 12M+ Linux systems. Qualys TRU discovered & validated. Learn attack paths, impact, and immediate mitigation steps. Patch now.

Qualys