Post B4Dqj93DsN8dNVkx72 by futurile@mastodon.social
 (DIR) More posts by futurile@mastodon.social
 (DIR) Post #B4DYnLxW1nylOXwZhA by civodul@toot.aquilenet.fr
       0 likes, 0 repeats
       
       “This ‘CrackArmor’ advisory exposes a confused-deputy flaw allowing unprivileged users to manipulate security profiles via pseudo-files, bypass user-namespace restrictions, and execute arbitrary code within the kernel.”https://blog.qualys.com/vulnerabilities-threat-research/2026/03/12/crackarmor-critical-apparmor-flaws-enable-local-privilege-escalation-to-rootThey mention getting sudo or Postfix to write to /sys/kernel/security/apparmor/.load & co. but the PoCs are not published yet.
       
 (DIR) Post #B4DcNBJLOUEQesvhc8 by abbe@bookwor.ms
       0 likes, 0 repeats
       
       @civodul PoC is in the actual advisory which has technical details
       
 (DIR) Post #B4Dqj93DsN8dNVkx72 by futurile@mastodon.social
       0 likes, 0 repeats
       
       @civodul oof