RSA Product/Service Type: Authentication Manager
The “CrackArmor” vulnerabilities are a set of local privilege escalation flaws in AppArmor’s Linux kernel code, discovered by Qualys in March 2026. They allow unprivileged users to escalate to root, bypass security controls, or cause denial of service.
Key Vulnerability Details:
1. CVE-2026-23268 – Policy Management Bypass
Link: https://nvd.nist.gov/vuln/detail/CVE-2026-23268
- Unprivileged user can load/remove/replace AppArmor profiles
- Allows complete policy control
- Leads to:
- Removal of confinement
- Privilege escalation
- Bypass of user namespace restrictions
2. CVE-2026-23269 – Out-of-Bounds Read
Link: https://nvd.nist.gov/vuln/detail/CVE-2026-23269
- Missing validation in DFA state handling
- Causes kernel memory out-of-bounds read
- Impact:
- Information disclosure (kernel memory)
- Potential DoS
- Possible LPE chaining
3. CVE-2026-23403 – Memory Leak
Link: https://nvd.nist.gov/vuln/detail/CVE-2026-23403
- Memory leak in verify_header function
- Can impact kernel stability and performance
4. CVE-2026-23404 – Stack Exhaustion (DoS)
Link: https://nvd.nist.gov/vuln/detail/CVE-2026-23404
- Recursive profile removal leads to:
- Kernel stack exhaustion
- System crash (kernel panic)
- Trigger: deeply nested AppArmor profiles (~1000 levels)
5. CVE-2026-23408 – Double Free / Use-After-Free
Link: https://nvd.nist.gov/vuln/detail/CVE-2026-23408
- Causes kernel memory corruption
- Potential impacts:
- Privilege escalation
- System compromise
6. Other CVEs (CVE-2026-23405 → CVE-2026-23411)
These additional CVEs include:
- Memory corruption issues
- Improper policy handling
- Namespace-related logic flaws
- Additional DoS / LPE primitives
All contribute to full exploit chains enabling:
- Root privilege escalation
- Container escape
- Security policy bypass
RSA Response:
All of these issues are only exploitable locally by an authenticated user on the system. RSA Authentication Manager provides access to the appliance through a single account, the appliance administrator (rsaadmin), which already has full root privileges.
These vulnerabilities do not introduce any additional risk beyond the existing access model and do not change the overall security posture of the appliance.
Related Articles
RSA Authentication Manager CVE-2017-1000367 sudo: Privilege escalation in via improper get_process_ttyname() parsing 20Number of Views View a Risk-Based Authentication Policy 5Number of Views Error message "Error: java.lang.IllegalArgumentException: Window boundary must be positive" in the RSA SecurID Authenticat… 120Number of Views The impact on RSA Authentication Manager 8.x of vulnerabilities reported in: OpenSSL Security Advisory - Dec 2015 - False … 66Number of Views CVE-2021-41617 Security vulnerability for RSA Authentication Manager 8.6.x 191Number of Views
Trending Articles
Authentication Manager Log Messages (23001-23091) How to Forward RSA Authentication Manager 8.4 or Later Logs to Multiple Syslog Servers Using rsyslog Customizing the Self-Service Console User Help RSA Authentication Manager Upgrade Process How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device