It was discovered that the AppArmor policy compiler incorrectly generated looser restrictions than expected for rules allowing mount operations. A local attacker could possibly use this to bypass AppArmor restrictions in applications where some mount operations were permitted.
{ "binaries": [ { "binary_name": "apparmor", "binary_version": "2.13.3-7ubuntu5.4" }, { "binary_name": "apparmor-dbgsym", "binary_version": "2.13.3-7ubuntu5.4" }, { "binary_name": "apparmor-easyprof", "binary_version": "2.13.3-7ubuntu5.4" }, { "binary_name": "apparmor-notify", "binary_version": "2.13.3-7ubuntu5.4" }, { "binary_name": "apparmor-profiles", "binary_version": "2.13.3-7ubuntu5.4" }, { "binary_name": "apparmor-utils", "binary_version": "2.13.3-7ubuntu5.4" }, { "binary_name": "dh-apparmor", "binary_version": "2.13.3-7ubuntu5.4" }, { "binary_name": "libapache2-mod-apparmor", "binary_version": "2.13.3-7ubuntu5.4" }, { "binary_name": "libapache2-mod-apparmor-dbgsym", "binary_version": "2.13.3-7ubuntu5.4" }, { "binary_name": "libapparmor-dev", "binary_version": "2.13.3-7ubuntu5.4" }, { "binary_name": "libapparmor-perl", "binary_version": "2.13.3-7ubuntu5.4" }, { "binary_name": "libapparmor-perl-dbgsym", "binary_version": "2.13.3-7ubuntu5.4" }, { "binary_name": "libapparmor1", "binary_version": "2.13.3-7ubuntu5.4" }, { "binary_name": "libapparmor1-dbgsym", "binary_version": "2.13.3-7ubuntu5.4" }, { "binary_name": "libpam-apparmor", "binary_version": "2.13.3-7ubuntu5.4" }, { "binary_name": "libpam-apparmor-dbgsym", "binary_version": "2.13.3-7ubuntu5.4" }, { "binary_name": "python3-apparmor", "binary_version": "2.13.3-7ubuntu5.4" }, { "binary_name": "python3-libapparmor", "binary_version": "2.13.3-7ubuntu5.4" }, { "binary_name": "python3-libapparmor-dbgsym", "binary_version": "2.13.3-7ubuntu5.4" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_name": "apparmor", "binary_version": "3.0.4-2ubuntu2.4" }, { "binary_name": "apparmor-dbgsym", "binary_version": "3.0.4-2ubuntu2.4" }, { "binary_name": "apparmor-notify", "binary_version": "3.0.4-2ubuntu2.4" }, { "binary_name": "apparmor-profiles", "binary_version": "3.0.4-2ubuntu2.4" }, { "binary_name": "apparmor-utils", "binary_version": "3.0.4-2ubuntu2.4" }, { "binary_name": "dh-apparmor", "binary_version": "3.0.4-2ubuntu2.4" }, { "binary_name": "libapache2-mod-apparmor", "binary_version": "3.0.4-2ubuntu2.4" }, { "binary_name": "libapache2-mod-apparmor-dbgsym", "binary_version": "3.0.4-2ubuntu2.4" }, { "binary_name": "libapparmor-dev", "binary_version": "3.0.4-2ubuntu2.4" }, { "binary_name": "libapparmor1", "binary_version": "3.0.4-2ubuntu2.4" }, { "binary_name": "libapparmor1-dbgsym", "binary_version": "3.0.4-2ubuntu2.4" }, { "binary_name": "libpam-apparmor", "binary_version": "3.0.4-2ubuntu2.4" }, { "binary_name": "libpam-apparmor-dbgsym", "binary_version": "3.0.4-2ubuntu2.4" }, { "binary_name": "python3-apparmor", "binary_version": "3.0.4-2ubuntu2.4" }, { "binary_name": "python3-libapparmor", "binary_version": "3.0.4-2ubuntu2.4" }, { "binary_name": "python3-libapparmor-dbgsym", "binary_version": "3.0.4-2ubuntu2.4" } ], "availability": "No subscription required" }