Impact
In the Linux kernel's AppArmor security module, an incorrect check allows a task that is already confined by a stack to improperly grant privileged transitions when moving through an unconfined profile in a user namespace. This flaw permits an escape from the confinement stack, enabling a process to gain higher privileges than intended. The weakness involves improper access control enforcement, undermining the isolation enforced by AppArmor and potentially allowing an attacker to execute arbitrary code with elevated privileges within the affected system.
Affected Systems
The affected products are all Linux kernel implementations that include the AppArmor module, as identified by the Linux:Linux vendor descriptor. No specific kernel release numbers are listed, so all versions of the Linux kernel that contain AppArmor remain vulnerable until an update that incorporates the patch is applied.
Risk and Exploitability
The CVSS score of 8.4 classifies this vulnerability as a high severity issue, while the EPSS score of less than 1% indicates a low probability of being actively exploited in the near term. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector requires the ability to execute the unconfined user namespace transition twice, implying a local or privilege-domained environment. If exploited, the attacker can escape the AppArmor confinement stack, effectively gaining privileged execution rights within the kernel space. The combination of high severity and low exploitation probability suggests that while the issue is critical, active attacks are currently unlikely, but the risk of impact remains if the flaw is discovered and exploited by an advanced adversary.
OpenCVE Enrichment