CrackArmor: 9 AppArmor Flaws Expose 12.6M Linux Nodes to Root Takeover
Hidden since 2017, nine AppArmor bugs let unprivileged users grab root and bust out of containers. Over 12.6 million Linux instances — think Kubernetes nodes — hang in the balance.
DevTools FeedApr 03, 20264 min read15 views
⚡ Key Takeaways
Nine AppArmor bugs enable root escalation and container escapes on 12.6M systems since 2017.𝕏
Kubernetes on Ubuntu/Debian most at risk; escape from pod to host nullifies isolation.𝕏
Patch immediately: Run aa-status and update kernels; SELinux users (RHEL) unaffected.𝕏
The 60-Second TL;DR
Nine AppArmor bugs enable root escalation and container escapes on 12.6M systems since 2017.
Kubernetes on Ubuntu/Debian most at risk; escape from pod to host nullifies isolation.
Patch immediately: Run aa-status and update kernels; SELinux users (RHEL) unaffected.