RSA Product/Service Type: Authentication Manager
The “CrackArmor” vulnerabilities are a set of local privilege escalation flaws in AppArmor’s Linux kernel code, discovered by Qualys in March 2026. They allow unprivileged users to escalate to root, bypass security controls, or cause denial of service.
Key Vulnerability Details:
1. CVE-2026-23268 – Policy Management Bypass
Link: https://nvd.nist.gov/vuln/detail/CVE-2026-23268
- Unprivileged user can load/remove/replace AppArmor profiles
- Allows complete policy control
- Leads to:
- Removal of confinement
- Privilege escalation
- Bypass of user namespace restrictions
2. CVE-2026-23269 – Out-of-Bounds Read
Link: https://nvd.nist.gov/vuln/detail/CVE-2026-23269
- Missing validation in DFA state handling
- Causes kernel memory out-of-bounds read
- Impact:
- Information disclosure (kernel memory)
- Potential DoS
- Possible LPE chaining
3. CVE-2026-23403 – Memory Leak
Link: https://nvd.nist.gov/vuln/detail/CVE-2026-23403
- Memory leak in verify_header function
- Can impact kernel stability and performance
4. CVE-2026-23404 – Stack Exhaustion (DoS)
Link: https://nvd.nist.gov/vuln/detail/CVE-2026-23404
- Recursive profile removal leads to:
- Kernel stack exhaustion
- System crash (kernel panic)
- Trigger: deeply nested AppArmor profiles (~1000 levels)
5. CVE-2026-23408 – Double Free / Use-After-Free
Link: https://nvd.nist.gov/vuln/detail/CVE-2026-23408
- Causes kernel memory corruption
- Potential impacts:
- Privilege escalation
- System compromise
6. Other CVEs (CVE-2026-23405 → CVE-2026-23411)
These additional CVEs include:
- Memory corruption issues
- Improper policy handling
- Namespace-related logic flaws
- Additional DoS / LPE primitives
All contribute to full exploit chains enabling:
- Root privilege escalation
- Container escape
- Security policy bypass
RSA Response:
All of these issues are only exploitable locally by an authenticated user on the system. RSA Authentication Manager provides access to the appliance through a single account, the appliance administrator (rsaadmin), which already has full root privileges.
These vulnerabilities do not introduce any additional risk beyond the existing access model and do not change the overall security posture of the appliance.
Related Articles
CVE-2021-41617 Security vulnerability for RSA Authentication Manager 8.6.x 191Number of Views RSA Authentication Manager CVE-2017-1000367 sudo: Privilege escalation in via improper get_process_ttyname() parsing 20Number of Views RSA Authentication Manager Multiple Vulnerabilities in PostgreSQL - False Positive 91Number of Views Bash bug Vulnerability (Shellshock) in RSA products 1.33KNumber of Views CERT/CC Vulnerability Note VU#144389: Potential Impact on RSA Products 201Number of Views
Trending Articles
RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU Authentication Manager How to Retrieve the LDAPS Certificate and Configure an External Identity Source to Use LDAPS How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device