CrackArmor: nine AppArmor flaws enable root access and container escape

Qualys has disclosed nine vulnerabilities collectively named CrackArmor in AppArmor, the security enforcement mechanism enabled by default on Ubuntu and Debian among others. The flaws have existed since 2017, starting with version v4.11, and according to the researchers affect more than 12.6 million enterprise systems. They allow privilege escalation to root and container escape. No official CVE identifiers exist yet, but Qualys worked with Ubuntu, Debian and SUSE on fixes ahead of publication.

What this means for your business

This is not a front door but a staircase: an attacker who already has a low-privilege foothold can become root or break out of a container onto the host. In containerised environments where isolation between customers or environments rests on AppArmor, one of the load-bearing assumptions disappears. That turns an otherwise contained incident into a serious one.

Berigo recommends

  • Apply the latest kernel packages from Ubuntu, Debian or SUSE to affected systems, prioritising hosts running containers from multiple environments.
  • Map where you actually rely on AppArmor for isolation and record it as an assumption in your architecture documentation.
  • Reduce the number of processes running with unnecessary privileges so a foothold offers less to build on.
  • Watch for CVE identifiers being assigned later and update your vulnerability register when they arrive.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch