Threat reportVulnerabilityTL-2026-0228
CrackArmor — 9 Linux AppArmor Confused Deputy Vulnerabilities Enable Root Privilege Escalation and Container Escape
CrackArmor — 9 Linux AppArmor Confused Deputy (TL-2026-0228), also tracked as CrackArmor, is a high-severity software vulnerability scored CVSS 8.4, first published 2026-03-14. It has no confirmed attribution, affects Linux Linux Kernel (AppArmor LSM), maps to 11 MITRE ATT&CK techniques (T1003, T1014, T1059), and is covered by 9 detection rules and 17 indicators of compromise.
- CVSS
- 8.4/10High
- CVEs
- 0None referenced
- Techniques
- 11MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 17Indicators of compromise
Key facts for TL-2026-0228
- Threat ID
- TL-2026-0228
- Also known as
- CrackArmor
- Severity
- HIGH
- CVSS
- 8.4 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- government, financial, healthcare, technology, telecommunications, energy, defense, cloud-services, education
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 17
How CrackArmor — 9 Linux AppArmor Confused Deputy works
Qualys Threat Research Unit discovered 9 confused deputy vulnerabilities in the Linux kernel AppArmor LSM module (kernel 4.11+ since 2017) affecting 12.6 million enterprise systems. Unprivileged local attackers can manipulate AppArmor security profiles via securityfs pseudo-files to achieve root privilege escalation, bypass container isolation, defeat KASLR, and cause denial of service via kernel stack exhaustion.
CrackArmor is a collection of nine vulnerabilities discovered by the Qualys Threat Research Unit (TRU) in the Linux kernel's AppArmor Linux Security Module (LSM). AppArmor is a mandatory access control (MAC) framework that confines programs to a limited set of resources, and is enabled by default on Ubuntu, Debian, and SUSE distributions. The vulnerabilities have existed since Linux kernel version 4.11 (2017), impacting an estimated 12.6 million enterprise Linux systems worldwide.
The core vulnerability class is "confused deputy" — AppArmor's securityfs pseudo-files (.load, .replace, .remove) under /sys/kernel/security/apparmor/ are created with world-writable permissions (mode 0666), allowing any unprivileged user to open them for writing. While direct writes fail with EACCES, attackers can use the dup2() syscall to redirect a privileged program's output (such as su in PTY mode) through these file descriptors, effectively loading, replacing, or removing arbitrary AppArmor profiles with full kernel privileges.
Vulnerability 1 (Confused Deputy, CWE-269): The fundamental flaw enabling all subsequent attacks. Unprivileged users open securityfs pseudo-files in O_WRONLY mode, then use dup2() to redirect privileged program stderr to these descriptors. The su command with -P (PTY) flag writes controlled binary data including null bytes, enabling arbitrary profile manipulation. This allows attackers to remove protective profiles from system services (rsyslogd, cupsd), load restrictive deny-all profiles causing denial of service, and bypass Ubuntu's unprivileged user-namespace restrictions.
Vulnerability 2 (Uncontrolled Recursion, CWE-674): The __remove_profile() function recursively calls itself via __aa_profile_list_release() without depth limits when processing nested subprofiles. An attacker can create deeply nested profile hierarchies (1024 levels: "a//x//x//x...") and trigger removal, exhausting the 16KB kernel stack on x86_64 systems. CONFIG_VMAP_STACK guard pages prevent arbitrary code execution, limiting impact to complete system crash (denial of service).
Vulnerability 3 (Out-of-Bounds Read, CWE-125): The match_char() macro evaluates arguments multiple times, causing the string pointer to increment multiple times due to MATCH_FLAG_DIFF_ENCODE logic. By crafting DFA matching patterns with wildcards followed by specific ranges, attackers can read up to 64KB past the allocated 8KB kmalloc buffer, disclosing KASLR-randomized kernel pointers including aa_global_buffers, shmem_ops, and noop_backing_dev_info addresses.
Vulnerability 4 (Use-After-Free, CWE-416): aa_loaddata structures in the kmalloc-192 slab cache are referenced by securityfs dentries without proper refcounting. A race condition exists between path_openat() acquiring a dentry reference and do_dentry_open() calling seq_rawdata_open(), while concurrent profile removal triggers kfree_sensitive() via delayed work. The race window can be widened to seconds by loading profiles with massive DFAs (~64K states). Exploitation on Ubuntu 24.04.3 involves cross-cache attacks, page table takeover via Jann Horn's technique (CVE-2020-29661), mapping /etc/passwd pages through re-allocated page tables, and writing a passwordless root entry. This is the most severe vulnerability, enabling reliable local privilege escalation to root.
Vulnerability 5 (Double-Free, CWE-415): In aa_replace_profiles(), the namespace name pointer ns_name is freed twice — first via aa_load_ent_free() at line 1262, then again via kfree(ns_name) at line 1270. The race window can be expanded to several seconds by writing 1024+ profiles with 16 subprofiles each. Exploitation on Debian 13.1 uses AF_PACKET page vectors and signalfd(-1) calls to achieve arbitrary credential modification, zeroing uid for root access. CONFIG_SLAB_BUCKETS is bypassed using user-key and AF_PACKET buffers.
Vulnerabilities 6-9 include a memory leak in verify_header(), missing namespace depth limits, out-of-bounds read/write in the DFA DEFAULT transition table, and an infinite loop in differential encoding verification.
A separate user-space local privilege escalation chain combines the confused deputy vulnerability with sudo and Postfix: loading an AppArmor profile that denies CAP_SETUID to /usr/bin/sudo causes sudo's setresuid() call to fail silently, then sudo executes sendmail (Postfix) while still running as root. The attacker controls Postfix configuration via the MAIL_CONFIG environment variable, achieving arbitrary code execution as root.
Patches were developed across 11 commits and merged upstream to Linus's kernel tree on 2026-03-12. Ubuntu, Debian, and SUSE have released corresponding security updates. No CVE identifiers have been assigned at the time of publication. PoC code has been withheld to allow patching, though detailed exploitation methodology is documented in the Qualys advisory.
MITRE ATT&CK techniques used in TL-2026-0228
credential-access
defense-evasion
T1014 Rootkit; T1078 Valid Accounts
execution
T1059 Command and Scripting Interpreter
privilege-escalation
T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism; T1611 Escape to Host
discovery
T1082 System Information Discovery
defense-impairment
T1222 File and Directory Permissions Modification; T1685 Disable or Modify Tools
impact
Affected products and versions in CrackArmor — 9 Linux AppArmor Confused Deputy
- Linux — Linux Kernel (AppArmor LSM)
Vulnerable versions: 4.11 through 6.x (all versions since 2017)
Fixed in: Patched upstream 2026-03-12 - Canonical — Ubuntu
Vulnerable versions: 14.04 LTS (Trusty); 16.04 LTS (Xenial); 18.04 LTS (Bionic); 20.04 LTS (Focal); 22.04 LTS (Jammy); 24.04 LTS (Noble); 25.10 (Questing Quokka)
Fixed in: Patched kernel packages available for all supported releases - Debian — Debian GNU/Linux
Vulnerable versions: All versions with AppArmor enabled
Fixed in: Security updates pending/available - SUSE — SUSE Linux Enterprise / openSUSE
Vulnerable versions: All versions with AppArmor enabled
Fixed in: Security updates pending/available - Canonical — sudo
Vulnerable versions: Versions prior to 1.9.15p5-3ubuntu5.24.04.2 (Noble); Versions prior to 1.9.9-1ubuntu2.6 (Jammy)
Fixed in: 1.9.15p5-3ubuntu5.24.04.2 (Noble); 1.9.9-1ubuntu2.6 (Jammy) - Canonical — util-linux
Vulnerable versions: Versions prior to 2.39.3-9ubuntu6.5 (Noble); Versions prior to 2.37.2-4ubuntu3.5 (Jammy)
Fixed in: 2.39.3-9ubuntu6.5 (Noble); 2.37.2-4ubuntu3.5 (Jammy)
Remediation for CrackArmor — 9 Linux AppArmor Confused Deputy
Patches
- Linux kernel patches: 11 commits merged upstream 2026-03-12
- Ubuntu: Kernel updates for Trusty through Questing Quokka (Launchpad Bug #2143853)
- Ubuntu sudo fix: Launchpad Bug #2143042
- Ubuntu util-linux fix: Launchpad Bug #2143850
- Sudo commit 3e474c2: Make setuid/setgid/setgroups failure fatal
- Upstream patches: PATCH 01-11/11 apparmor series
Immediate actions
- Apply kernel security updates immediately on all Ubuntu, Debian, and SUSE systems
- Run sudo apt update && sudo apt upgrade on Debian/Ubuntu systems
- Reboot systems after kernel updates to load patched kernel
- Update sudo package to patched versions (1.9.15p5-3ubuntu5.24.04.2 on Noble, 1.9.9-1ubuntu2.6 on Jammy)
- Update util-linux package to hardened versions (2.39.3-9ubuntu6.5 on Noble, 2.37.2-4ubuntu3.5 on Jammy)
- Monitor for unauthorized AppArmor profile modifications via auditd
- Restrict access to /sys/kernel/security/apparmor/ pseudo-files where possible
Workarounds
- Restrict permissions on /sys/kernel/security/apparmor/.load, .replace, .remove files
- Disable AppArmor if not required (reduces attack surface but removes MAC protections)
- Limit local user access on critical systems until patches are applied
- Monitor for anomalous su -P usage and MAIL_CONFIG environment variable manipulation
Longer-term hardening
- Deploy kernel live-patching solutions for rapid vulnerability response
- Implement auditd rules monitoring securityfs write operations
- Deploy EDR with behavioral detection for privilege escalation patterns
- Restrict unprivileged user namespace creation where not needed
- Implement container runtime security monitoring for escape attempts
- Review and harden AppArmor profile configurations across fleet
- Enable CONFIG_VMAP_STACK to mitigate stack exhaustion attacks
Weaknesses (CWE) in CrackArmor — 9 Linux AppArmor Confused Deputy
Timeline of CrackArmor — 9 Linux AppArmor Confused Deputy
- Vulnerable AppArmor securityfs pseudo-file permissions introduced in Linux kernel v4.11
- Qualys TRU reports first batch of AppArmor vulnerabilities to Ubuntu/Canonical security team
- Additional vulnerability batches sent to Ubuntu/Canonical security team
- Disclosure coordination concerns raised between Qualys and vendors
- Continued disclosure timeline discussions between Qualys TRU and affected vendors
- Coordinated public disclosure date set for March 3, 2026 (later shifted to March 12)
- Patch development iterations begin; 5 versions developed through March 5
- Final patch version (v5) completed covering all 9 vulnerabilities across 11 commits
- Qualys TRU publishes CrackArmor advisory; Ubuntu releases kernel, sudo, and util-linux security updates
- All 11 AppArmor patches merged upstream to Linus Torvalds' kernel tree
- Widespread media coverage begins; The Hacker News and security outlets report on CrackArmor findings
- As of 2026-05-29, CrackArmor (9 Linux AppArmor LPE flaws) remains PATCHED: upstream kernel fixes merged 2026-03-12 with Ubuntu/Debian/SUSE/Azure Linux updates shipping, and CVE-2026-23268 through -23411 now assigned. No in-the-wild exploitation or CISA KEV listing reported; Qualys still withholds PoC and exploitation needs local access.
Sources cited for CrackArmor — 9 Linux AppArmor Confused Deputy
- CrackArmor: Critical AppArmor Flaws Enable Local Privilege Escalation to Root — Qualys Blog
- CrackArmor Technical Advisory — Qualys TRU
- Nine CrackArmor Flaws in Linux AppArmor Enable Root Escalation, Bypass Container Isolation — The Hacker News
- AppArmor Vulnerability Fixes Available — Ubuntu Blog
- CrackArmor Vulnerabilities — Ubuntu Security
- Linux Kernel AppArmor Bug — Launchpad #2143853
- Sudo Bug — Launchpad #2143042
- Util-linux Bug — Launchpad #2143850
Detection coverage for TL-2026-0228
As of 2026-03-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0228 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.