CrackArmor: Critical AppArmor Flaws Enable Local Privilege Escalation to Root

2026-03-13T08:51:52Zd15217c2044ccadb3ccddf72a4cc2783943ca3b85c0b22f5863422e784d98d37
LPEapparmorconfused deputycontainer escapecrackarmorkernel vulnerabilitylinux kernellocal privilege escalationpatchingprivilege escalationqualys truvulnerability disclosure

What happened

Qualys Threat Research Unit (TRU) disclosed “CrackArmor,” a set of confused-deputy vulnerabilities in AppArmor that allow unprivileged users to bypass kernel protections, achieve local privilege escalation to root, and break container isolation. The flaws have existed since 2017 and are estimated to affect over 12.6 million systems globally. Qualys recommends immediate kernel patching to neutralize the issues.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
qualys_blog
Record identifier
d15217c2044ccadb3ccddf72a4cc2783943ca3b85c0b22f5863422e784d98d37
Enrichment time
2026-03-13T08:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CrackArmor: Critical AppArmor Flaws Enable Local Privilege Escalation to Root · Baitaphish