AppArmor Local Privilege Escalation Vulnerability for RSA Authentication Manager (CrackArmor)
3 days ago
Originally Published: 2026-06-02
Article Number
000073951
Applies To

RSA Product/Service Type: Authentication Manager

CVE Identifier(s)
CVE-2026-23268,CVE-2026-23269,CVE-2026-23403,CVE-2026-23404,CVE-2026-23405,CVE-2026-23406,CVE-2026-23407,CVE-2026-23408,CVE-2026-23409,CVE-2026-23410,CVE-2026-23411
Article Summary

The “CrackArmor” vulnerabilities are a set of local privilege escalation flaws in AppArmor’s Linux kernel code, discovered by Qualys in March 2026. They allow unprivileged users to escalate to root, bypass security controls, or cause denial of service.

 

Key Vulnerability Details:

 

1. CVE-2026-23268 – Policy Management Bypass 

Link: https://nvd.nist.gov/vuln/detail/CVE-2026-23268

  • Unprivileged user can load/remove/replace AppArmor profiles
  • Allows complete policy control
  • Leads to:
    • Removal of confinement
    • Privilege escalation
    • Bypass of user namespace restrictions

 

2. CVE-2026-23269 – Out-of-Bounds Read 

Link: https://nvd.nist.gov/vuln/detail/CVE-2026-23269

  • Missing validation in DFA state handling
  • Causes kernel memory out-of-bounds read
  • Impact:
    • Information disclosure (kernel memory)
    • Potential DoS
    • Possible LPE chaining

 

3. CVE-2026-23403 – Memory Leak

Link: https://nvd.nist.gov/vuln/detail/CVE-2026-23403

  • Memory leak in verify_header function
  • Can impact kernel stability and performance

 

4. CVE-2026-23404 – Stack Exhaustion (DoS)

Link: https://nvd.nist.gov/vuln/detail/CVE-2026-23404

  • Recursive profile removal leads to:
    • Kernel stack exhaustion
    • System crash (kernel panic)
  • Trigger: deeply nested AppArmor profiles (~1000 levels)

 

5. CVE-2026-23408 – Double Free / Use-After-Free

Link: https://nvd.nist.gov/vuln/detail/CVE-2026-23408

  • Causes kernel memory corruption
  • Potential impacts:
    • Privilege escalation
    • System compromise 

 

6. Other CVEs (CVE-2026-23405 → CVE-2026-23411)

These additional CVEs include:

  • Memory corruption issues
  • Improper policy handling
  • Namespace-related logic flaws
  • Additional DoS / LPE primitives

All contribute to full exploit chains enabling:

  • Root privilege escalation
  • Container escape
  • Security policy bypass
Alert Impact
Not Exploitable
Alert Impact Explanation

RSA Response:

 

All of these issues are only exploitable locally by an authenticated user on the system. RSA Authentication Manager provides access to the appliance through a single account, the appliance administrator (rsaadmin), which already has full root privileges.

These vulnerabilities do not introduce any additional risk beyond the existing access model and do not change the overall security posture of the appliance.

Disclaimer
Read and use the information in this RSA Security Advisory to assist in avoiding any situation that might arise from the problems described herein. If you have any questions regarding this product alert, contact RSA Technical Support at 1-800-995-5095. RSA Security LLC and its affiliates distribute RSA Security Advisories in order to bring to the attention of users of the affected RSA products, important security information. RSA recommends that all users determine the applicability of this information to their individual situations and take appropriate action. The information set forth herein is provided 'as is' without warranty of any kind. RSA disclaims all warranties, either express or implied, including the warranties of merchantability, fitness for a particular purpose, title and non-infringement. In no event shall RSA, its affiliates, or suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if RSA, its affiliates, or suppliers have been advised of the possibility of such damages. Some jurisdictions do not allow the exclusion or limitation of liability for consequential or incidental damages, so the foregoing limitation may not apply.