Threat reportVulnerabilityTL-2026-0228

CrackArmor — 9 Linux AppArmor Confused Deputy Vulnerabilities Enable Root Privilege Escalation and Container Escape

highPATCHED

CrackArmor — 9 Linux AppArmor Confused Deputy (TL-2026-0228), also tracked as CrackArmor, is a high-severity software vulnerability scored CVSS 8.4, first published 2026-03-14. It has no confirmed attribution, affects Linux Linux Kernel (AppArmor LSM), maps to 11 MITRE ATT&CK techniques (T1003, T1014, T1059), and is covered by 9 detection rules and 17 indicators of compromise.

CVSS
8.4/10High
CVEs
0None referenced
Techniques
11MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
17Indicators of compromise

Key facts for TL-2026-0228

Threat ID
TL-2026-0228
Also known as
CrackArmor
Severity
HIGH
CVSS
8.4 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
government, financial, healthcare, technology, telecommunications, energy, defense, cloud-services, education
Target regions
Global
Detection rules
9
Indicators of compromise
17

How CrackArmor — 9 Linux AppArmor Confused Deputy works

Qualys Threat Research Unit discovered 9 confused deputy vulnerabilities in the Linux kernel AppArmor LSM module (kernel 4.11+ since 2017) affecting 12.6 million enterprise systems. Unprivileged local attackers can manipulate AppArmor security profiles via securityfs pseudo-files to achieve root privilege escalation, bypass container isolation, defeat KASLR, and cause denial of service via kernel stack exhaustion.

CrackArmor is a collection of nine vulnerabilities discovered by the Qualys Threat Research Unit (TRU) in the Linux kernel's AppArmor Linux Security Module (LSM). AppArmor is a mandatory access control (MAC) framework that confines programs to a limited set of resources, and is enabled by default on Ubuntu, Debian, and SUSE distributions. The vulnerabilities have existed since Linux kernel version 4.11 (2017), impacting an estimated 12.6 million enterprise Linux systems worldwide.

The core vulnerability class is "confused deputy" — AppArmor's securityfs pseudo-files (.load, .replace, .remove) under /sys/kernel/security/apparmor/ are created with world-writable permissions (mode 0666), allowing any unprivileged user to open them for writing. While direct writes fail with EACCES, attackers can use the dup2() syscall to redirect a privileged program's output (such as su in PTY mode) through these file descriptors, effectively loading, replacing, or removing arbitrary AppArmor profiles with full kernel privileges.

Vulnerability 1 (Confused Deputy, CWE-269): The fundamental flaw enabling all subsequent attacks. Unprivileged users open securityfs pseudo-files in O_WRONLY mode, then use dup2() to redirect privileged program stderr to these descriptors. The su command with -P (PTY) flag writes controlled binary data including null bytes, enabling arbitrary profile manipulation. This allows attackers to remove protective profiles from system services (rsyslogd, cupsd), load restrictive deny-all profiles causing denial of service, and bypass Ubuntu's unprivileged user-namespace restrictions.

Vulnerability 2 (Uncontrolled Recursion, CWE-674): The __remove_profile() function recursively calls itself via __aa_profile_list_release() without depth limits when processing nested subprofiles. An attacker can create deeply nested profile hierarchies (1024 levels: "a//x//x//x...") and trigger removal, exhausting the 16KB kernel stack on x86_64 systems. CONFIG_VMAP_STACK guard pages prevent arbitrary code execution, limiting impact to complete system crash (denial of service).

Vulnerability 3 (Out-of-Bounds Read, CWE-125): The match_char() macro evaluates arguments multiple times, causing the string pointer to increment multiple times due to MATCH_FLAG_DIFF_ENCODE logic. By crafting DFA matching patterns with wildcards followed by specific ranges, attackers can read up to 64KB past the allocated 8KB kmalloc buffer, disclosing KASLR-randomized kernel pointers including aa_global_buffers, shmem_ops, and noop_backing_dev_info addresses.

Vulnerability 4 (Use-After-Free, CWE-416): aa_loaddata structures in the kmalloc-192 slab cache are referenced by securityfs dentries without proper refcounting. A race condition exists between path_openat() acquiring a dentry reference and do_dentry_open() calling seq_rawdata_open(), while concurrent profile removal triggers kfree_sensitive() via delayed work. The race window can be widened to seconds by loading profiles with massive DFAs (~64K states). Exploitation on Ubuntu 24.04.3 involves cross-cache attacks, page table takeover via Jann Horn's technique (CVE-2020-29661), mapping /etc/passwd pages through re-allocated page tables, and writing a passwordless root entry. This is the most severe vulnerability, enabling reliable local privilege escalation to root.

Vulnerability 5 (Double-Free, CWE-415): In aa_replace_profiles(), the namespace name pointer ns_name is freed twice — first via aa_load_ent_free() at line 1262, then again via kfree(ns_name) at line 1270. The race window can be expanded to several seconds by writing 1024+ profiles with 16 subprofiles each. Exploitation on Debian 13.1 uses AF_PACKET page vectors and signalfd(-1) calls to achieve arbitrary credential modification, zeroing uid for root access. CONFIG_SLAB_BUCKETS is bypassed using user-key and AF_PACKET buffers.

Vulnerabilities 6-9 include a memory leak in verify_header(), missing namespace depth limits, out-of-bounds read/write in the DFA DEFAULT transition table, and an infinite loop in differential encoding verification.

A separate user-space local privilege escalation chain combines the confused deputy vulnerability with sudo and Postfix: loading an AppArmor profile that denies CAP_SETUID to /usr/bin/sudo causes sudo's setresuid() call to fail silently, then sudo executes sendmail (Postfix) while still running as root. The attacker controls Postfix configuration via the MAIL_CONFIG environment variable, achieving arbitrary code execution as root.

Patches were developed across 11 commits and merged upstream to Linus's kernel tree on 2026-03-12. Ubuntu, Debian, and SUSE have released corresponding security updates. No CVE identifiers have been assigned at the time of publication. PoC code has been withheld to allow patching, though detailed exploitation methodology is documented in the Qualys advisory.

MITRE ATT&CK techniques used in TL-2026-0228

credential-access

T1003 OS Credential Dumping

defense-evasion

T1014 Rootkit; T1078 Valid Accounts

execution

T1059 Command and Scripting Interpreter

privilege-escalation

T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism; T1611 Escape to Host

discovery

T1082 System Information Discovery

defense-impairment

T1222 File and Directory Permissions Modification; T1685 Disable or Modify Tools

impact

T1499 Endpoint Denial of Service

Affected products and versions in CrackArmor — 9 Linux AppArmor Confused Deputy

  • Linux — Linux Kernel (AppArmor LSM)
    Vulnerable versions: 4.11 through 6.x (all versions since 2017)
    Fixed in: Patched upstream 2026-03-12
  • Canonical — Ubuntu
    Vulnerable versions: 14.04 LTS (Trusty); 16.04 LTS (Xenial); 18.04 LTS (Bionic); 20.04 LTS (Focal); 22.04 LTS (Jammy); 24.04 LTS (Noble); 25.10 (Questing Quokka)
    Fixed in: Patched kernel packages available for all supported releases
  • Debian — Debian GNU/Linux
    Vulnerable versions: All versions with AppArmor enabled
    Fixed in: Security updates pending/available
  • SUSE — SUSE Linux Enterprise / openSUSE
    Vulnerable versions: All versions with AppArmor enabled
    Fixed in: Security updates pending/available
  • Canonical — sudo
    Vulnerable versions: Versions prior to 1.9.15p5-3ubuntu5.24.04.2 (Noble); Versions prior to 1.9.9-1ubuntu2.6 (Jammy)
    Fixed in: 1.9.15p5-3ubuntu5.24.04.2 (Noble); 1.9.9-1ubuntu2.6 (Jammy)
  • Canonical — util-linux
    Vulnerable versions: Versions prior to 2.39.3-9ubuntu6.5 (Noble); Versions prior to 2.37.2-4ubuntu3.5 (Jammy)
    Fixed in: 2.39.3-9ubuntu6.5 (Noble); 2.37.2-4ubuntu3.5 (Jammy)

Remediation for CrackArmor — 9 Linux AppArmor Confused Deputy

Patches

  • Linux kernel patches: 11 commits merged upstream 2026-03-12
  • Ubuntu: Kernel updates for Trusty through Questing Quokka (Launchpad Bug #2143853)
  • Ubuntu sudo fix: Launchpad Bug #2143042
  • Ubuntu util-linux fix: Launchpad Bug #2143850
  • Sudo commit 3e474c2: Make setuid/setgid/setgroups failure fatal
  • Upstream patches: PATCH 01-11/11 apparmor series

Immediate actions

  • Apply kernel security updates immediately on all Ubuntu, Debian, and SUSE systems
  • Run sudo apt update && sudo apt upgrade on Debian/Ubuntu systems
  • Reboot systems after kernel updates to load patched kernel
  • Update sudo package to patched versions (1.9.15p5-3ubuntu5.24.04.2 on Noble, 1.9.9-1ubuntu2.6 on Jammy)
  • Update util-linux package to hardened versions (2.39.3-9ubuntu6.5 on Noble, 2.37.2-4ubuntu3.5 on Jammy)
  • Monitor for unauthorized AppArmor profile modifications via auditd
  • Restrict access to /sys/kernel/security/apparmor/ pseudo-files where possible

Workarounds

  • Restrict permissions on /sys/kernel/security/apparmor/.load, .replace, .remove files
  • Disable AppArmor if not required (reduces attack surface but removes MAC protections)
  • Limit local user access on critical systems until patches are applied
  • Monitor for anomalous su -P usage and MAIL_CONFIG environment variable manipulation

Longer-term hardening

  • Deploy kernel live-patching solutions for rapid vulnerability response
  • Implement auditd rules monitoring securityfs write operations
  • Deploy EDR with behavioral detection for privilege escalation patterns
  • Restrict unprivileged user namespace creation where not needed
  • Implement container runtime security monitoring for escape attempts
  • Review and harden AppArmor profile configurations across fleet
  • Enable CONFIG_VMAP_STACK to mitigate stack exhaustion attacks

Weaknesses (CWE) in CrackArmor — 9 Linux AppArmor Confused Deputy

CWE-269, CWE-674, CWE-125, CWE-416, CWE-415

Timeline of CrackArmor — 9 Linux AppArmor Confused Deputy

  • Vulnerable AppArmor securityfs pseudo-file permissions introduced in Linux kernel v4.11
  • Qualys TRU reports first batch of AppArmor vulnerabilities to Ubuntu/Canonical security team
  • Additional vulnerability batches sent to Ubuntu/Canonical security team
  • Disclosure coordination concerns raised between Qualys and vendors
  • Continued disclosure timeline discussions between Qualys TRU and affected vendors
  • Coordinated public disclosure date set for March 3, 2026 (later shifted to March 12)
  • Patch development iterations begin; 5 versions developed through March 5
  • Final patch version (v5) completed covering all 9 vulnerabilities across 11 commits
  • Qualys TRU publishes CrackArmor advisory; Ubuntu releases kernel, sudo, and util-linux security updates
  • All 11 AppArmor patches merged upstream to Linus Torvalds' kernel tree
  • Widespread media coverage begins; The Hacker News and security outlets report on CrackArmor findings
  • As of 2026-05-29, CrackArmor (9 Linux AppArmor LPE flaws) remains PATCHED: upstream kernel fixes merged 2026-03-12 with Ubuntu/Debian/SUSE/Azure Linux updates shipping, and CVE-2026-23268 through -23411 now assigned. No in-the-wild exploitation or CISA KEV listing reported; Qualys still withholds PoC and exploitation needs local access.

Sources cited for CrackArmor — 9 Linux AppArmor Confused Deputy

Detection coverage for TL-2026-0228

As of 2026-03-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0228 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
17 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats