CrackArmor: Critical AppArmor Flaws Enable Local Privilege Escalation to Root
2026-03-13T08:51:52Z•d15217c2044ccadb3ccddf72a4cc2783943ca3b85c0b22f5863422e784d98d37
LPEapparmorconfused deputycontainer escapecrackarmorkernel vulnerabilitylinux kernellocal privilege escalationpatchingprivilege escalationqualys truvulnerability disclosure
What happened
Qualys Threat Research Unit (TRU) disclosed “CrackArmor,” a set of confused-deputy vulnerabilities in AppArmor that allow unprivileged users to bypass kernel protections, achieve local privilege escalation to root, and break container isolation. The flaws have existed since 2017 and are estimated to affect over 12.6 million systems globally. Qualys recommends immediate kernel patching to neutralize the issues.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- qualys_blog
- Record identifier
- d15217c2044ccadb3ccddf72a4cc2783943ca3b85c0b22f5863422e784d98d37
- Enrichment time
- 2026-03-13T08:51:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.