RSA Product/Service Type: Authentication Manager
The “CrackArmor” vulnerabilities are a set of local privilege escalation flaws in AppArmor’s Linux kernel code, discovered by Qualys in March 2026. They allow unprivileged users to escalate to root, bypass security controls, or cause denial of service.
Key Vulnerability Details:
1. CVE-2026-23268 – Policy Management Bypass
Link: https://nvd.nist.gov/vuln/detail/CVE-2026-23268
- Unprivileged user can load/remove/replace AppArmor profiles
- Allows complete policy control
- Leads to:
- Removal of confinement
- Privilege escalation
- Bypass of user namespace restrictions
2. CVE-2026-23269 – Out-of-Bounds Read
Link: https://nvd.nist.gov/vuln/detail/CVE-2026-23269
- Missing validation in DFA state handling
- Causes kernel memory out-of-bounds read
- Impact:
- Information disclosure (kernel memory)
- Potential DoS
- Possible LPE chaining
3. CVE-2026-23403 – Memory Leak
Link: https://nvd.nist.gov/vuln/detail/CVE-2026-23403
- Memory leak in verify_header function
- Can impact kernel stability and performance
4. CVE-2026-23404 – Stack Exhaustion (DoS)
Link: https://nvd.nist.gov/vuln/detail/CVE-2026-23404
- Recursive profile removal leads to:
- Kernel stack exhaustion
- System crash (kernel panic)
- Trigger: deeply nested AppArmor profiles (~1000 levels)
5. CVE-2026-23408 – Double Free / Use-After-Free
Link: https://nvd.nist.gov/vuln/detail/CVE-2026-23408
- Causes kernel memory corruption
- Potential impacts:
- Privilege escalation
- System compromise
6. Other CVEs (CVE-2026-23405 → CVE-2026-23411)
These additional CVEs include:
- Memory corruption issues
- Improper policy handling
- Namespace-related logic flaws
- Additional DoS / LPE primitives
All contribute to full exploit chains enabling:
- Root privilege escalation
- Container escape
- Security policy bypass
RSA Response:
All of these issues are only exploitable locally by an authenticated user on the system. RSA Authentication Manager provides access to the appliance through a single account, the appliance administrator (rsaadmin), which already has full root privileges.
These vulnerabilities do not introduce any additional risk beyond the existing access model and do not change the overall security posture of the appliance.
Related Articles
RSA Authentication Manager CVE-2017-1000367 sudo: Privilege escalation in via improper get_process_ttyname() parsing 20Number of Views View a Risk-Based Authentication Policy 5Number of Views The impact on RSA Authentication Manager 8.x of vulnerabilities reported in: OpenSSL Security Advisory - Dec 2015 - False … 66Number of Views Error message "Error: java.lang.IllegalArgumentException: Window boundary must be positive" in the RSA SecurID Authenticat… 120Number of Views CVE-2021-41617 Security vulnerability for RSA Authentication Manager 8.6.x 191Number of Views
Trending Articles
Unable to login to RSA Authentication Manager Security Console as super admin Authentication Manager Administration Server with operations console service Fails to Start with "No config.xml Was Found"… Authentication Manager Security Console and Operations Console Inaccessible After Certificate Update RSA Authentication Manager Upgrade Process Authentication Manager How to Retrieve the LDAPS Certificate and Configure an External Identity Source to Use LDAPS