Qualys Threat Research Unit disclosed nine AppArmor vulnerabilities, collectively named CrackArmor, that allow unprivileged local users to manipulate AppArmor policy handling, escalate privileges to root, trigger denial-of-service conditions, and weaken or bypass container isolation on affected Linux systems. The flaws reportedly stem from AppArmor’s implementation in the Linux kernel rather than its security model, have existed since around 2017, and affect distributions where AppArmor is widely enabled by default, including Ubuntu, Debian, and SUSE. Researchers said the issues can be abused as confused deputy flaws, in which low-privileged users coerce trusted privileged programs into performing restricted actions on their behalf.
Public reporting says attackers can target AppArmor pseudo-files such as /sys/kernel/security/apparmor/.load, .replace, and .remove, using privileged tools including Sudo and Postfix as proxies to bypass namespace restrictions and potentially achieve kernel-level code execution. Reported impacts include local privilege escalation, service protection bypass, denial of service through policy abuse or stack exhaustion, and possible KASLR bypass via out-of-bounds reads; one report also estimates exposure at more than 12.6 million enterprise Linux instances with AppArmor enabled. No CVE identifiers had been assigned at the time of reporting, but the disclosure is significant because it affects a core Linux security control relied on in enterprise servers, cloud environments, and Kubernetes deployments.

Get the actors, campaigns, and ATT&CK mapping behind it.
17 events from the most recent confirmed update back to the earliest known activity.
In an oss-sec discussion, after AppArmor maintainer John Johansen said the seven disputed AppArmor flaws likely deserved identifiers, Greg Kroah-Hartman agreed to assign CVEs for the remaining issues. The decision reversed the prior refusal to classify those seven bugs as separate vulnerabilities.
In an oss-sec follow-up, AppArmor maintainer John Johansen said the seven additional AppArmor flaws should probably receive CVEs because Incus/LXD can actively enable AppArmor policy namespaces for containers, creating exploitable conditions. He reiterated that the LXD policy-namespace feature introduced the local privilege-escalation scenario and pointed to disabling unprivileged_userns_apparmor_policy as mitigation.
In an oss-sec discussion, AppArmor maintainer John Johansen said the seven disputed flaws are generally exploitable from a user namespace only when a privileged setup ties an AppArmor policy namespace to the container and allows policy loading. He attributed the local privilege-escalation condition to the LXD/Incus behavior enabling that setup and recommended setting unprivileged_userns_apparmor_policy to false to block container-root policy loading as a mitigation.
Qualys publicly disputed the kernel CVE team's decision not to assign separate CVEs to seven remaining AppArmor vulnerabilities, arguing they can be triggered by attackers inside containers allowed to manage their own AppArmor namespaces. The company requested either CVE assignment for the seven issues or rejection of CVE-2026-23269, saying it was not materially different from the others.
In an oss-sec follow-up, Greg Kroah-Hartman said the seven remaining AppArmor issues disclosed by Qualys were not being classified as separate vulnerabilities because they were understood to require elevated privileges to trigger. He added that additional CVEs could still be assigned if the AppArmor maintainer determined the bugs should be treated as individual vulnerabilities.
Qualys followed up with the Linux kernel CVE assignment team after fixes released on March 12, stating that two of the nine AppArmor flaws had already been assigned CVE-2026-23268 and CVE-2026-23269 and requesting identifiers for the other seven. The message also detailed the remaining bug classes, including memory leak, recursion, out-of-bounds access, double free, infinite loop, and a use-after-free race, and linked them to specific stable kernel patch commits.
According to reporting, CISA and DHS issued emergency bulletins warning critical infrastructure sectors including energy, water, and defense about the CrackArmor AppArmor vulnerabilities. The alerts highlighted the risk posed by the newly disclosed Linux privilege-escalation and container-bypass flaws.
Alongside disclosure, Qualys said it had developed proof-of-concept exploit chains using trusted tools such as sudo and Postfix but would not release exploit code publicly. Researchers urged organizations to apply kernel and AppArmor updates immediately and monitor for unauthorized AppArmor profile changes.
Qualys Threat Research Unit disclosed nine critical AppArmor vulnerabilities collectively named CrackArmor, warning they could let unprivileged local users gain root, bypass security policies, escape containers, and crash systems. The company said the flaws affect kernels since 4.11 and potentially expose about 12.6 million enterprise Linux systems, especially on Ubuntu, Debian, and SUSE.
CERT.at published an advisory about multiple AppArmor vulnerabilities dubbed CrackArmor and indicated that updates were available. This marked public availability of remediation guidance for affected users.
Before public disclosure, Qualys coordinated the AppArmor vulnerability findings with Ubuntu, Debian, SUSE, and Sudo maintainers so fixes could be prepared. This vendor coordination preceded public advisories and patch guidance.
A Linux stable-kernel commit added a hard limit of 32 levels for AppArmor policy namespaces and changed namespace creation to fail when the cap is exceeded. The patch, reported by Qualys Security Advisory, addressed a resource-exhaustion issue caused by arbitrarily deep policy namespace nesting.
A Linux stable-kernel commit fixed a memory leak in AppArmor's verify_header function in policy_unpack.c, where resetting *ns to NULL on each call leaked previously allocated namespace strings and broke namespace consistency checks when unpacking multiple profiles. The patch removed the incorrect assignment, was reported by Qualys, and fixed a flaw later included in the CrackArmor vulnerability set.
A Linux stable-kernel commit changed AppArmor's profile removal code from a recursive cleanup path to an iterative approach for removing child profiles and related filesystem/list entries. The patch appears to address one of the AppArmor bugs later discussed as part of the CrackArmor vulnerability set.
A Sudo commit fixed a fail-open condition in exec_mailer() that could allow mail-sending to proceed even when privilege-dropping failed. Later reporting connected this bug to a CrackArmor exploit chain involving AppArmor profile manipulation and Postfix sendmail behavior.
A Linux stable-kernel commit fixed a double-free bug in AppArmor's aa_replace_profiles() by transferring ownership of ns_name safely after assignment. The patch, credited to a Qualys Security Advisory, addressed a flaw later associated with the CrackArmor vulnerability set.
The nine vulnerabilities later named CrackArmor originated in AppArmor's Linux Security Module implementation starting with Linux kernel version 4.11. This left affected systems exposed for years on distributions that enable AppArmor by default.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
22 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourcewatchguard.com
Open sourceseclists.org
Open sourceseclists.org
Open sourcegit.kernel.org
Open sourcegit.kernel.org
Open sourcegit.kernel.org
Open sourcegit.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.