RSA Product/Service Type: Authentication Manager
The “CrackArmor” vulnerabilities are a set of local privilege escalation flaws in AppArmor’s Linux kernel code, discovered by Qualys in March 2026. They allow unprivileged users to escalate to root, bypass security controls, or cause denial of service.
Key Vulnerability Details:
1. CVE-2026-23268 – Policy Management Bypass
Link: https://nvd.nist.gov/vuln/detail/CVE-2026-23268
- Unprivileged user can load/remove/replace AppArmor profiles
- Allows complete policy control
- Leads to:
- Removal of confinement
- Privilege escalation
- Bypass of user namespace restrictions
2. CVE-2026-23269 – Out-of-Bounds Read
Link: https://nvd.nist.gov/vuln/detail/CVE-2026-23269
- Missing validation in DFA state handling
- Causes kernel memory out-of-bounds read
- Impact:
- Information disclosure (kernel memory)
- Potential DoS
- Possible LPE chaining
3. CVE-2026-23403 – Memory Leak
Link: https://nvd.nist.gov/vuln/detail/CVE-2026-23403
- Memory leak in verify_header function
- Can impact kernel stability and performance
4. CVE-2026-23404 – Stack Exhaustion (DoS)
Link: https://nvd.nist.gov/vuln/detail/CVE-2026-23404
- Recursive profile removal leads to:
- Kernel stack exhaustion
- System crash (kernel panic)
- Trigger: deeply nested AppArmor profiles (~1000 levels)
5. CVE-2026-23408 – Double Free / Use-After-Free
Link: https://nvd.nist.gov/vuln/detail/CVE-2026-23408
- Causes kernel memory corruption
- Potential impacts:
- Privilege escalation
- System compromise
6. Other CVEs (CVE-2026-23405 → CVE-2026-23411)
These additional CVEs include:
- Memory corruption issues
- Improper policy handling
- Namespace-related logic flaws
- Additional DoS / LPE primitives
All contribute to full exploit chains enabling:
- Root privilege escalation
- Container escape
- Security policy bypass
RSA Response:
All of these issues are only exploitable locally by an authenticated user on the system. RSA Authentication Manager provides access to the appliance through a single account, the appliance administrator (rsaadmin), which already has full root privileges.
These vulnerabilities do not introduce any additional risk beyond the existing access model and do not change the overall security posture of the appliance.
Related Articles
RSA Authentication Manager CVE-2017-1000367 sudo: Privilege escalation in via improper get_process_ttyname() parsing 20Number of Views Final Notice: Permanent Shutdown of Non-Company-Specific URLs 12Number of Views View a Risk-Based Authentication Policy 5Number of Views RSA Authentication Manager 8.7 False Positive Security Vulnerabilities 136Number of Views RSA Authentication Manager 8.x Security Vulnerabilities for NTPD - False Positive 96Number of Views