It was discovered that the AppArmor policy compiler incorrectly generated looser restrictions than expected for rules allowing mount operations. A local attacker could possibly use this to bypass AppArmor restrictions in applications where some mount operations were permitted.
{ "availability": "No subscription required", "binaries": [ { "binary_version": "2.13.3-7ubuntu5.4", "binary_name": "apparmor" }, { "binary_version": "2.13.3-7ubuntu5.4", "binary_name": "apparmor-dbgsym" }, { "binary_version": "2.13.3-7ubuntu5.4", "binary_name": "apparmor-easyprof" }, { "binary_version": "2.13.3-7ubuntu5.4", "binary_name": "apparmor-notify" }, { "binary_version": "2.13.3-7ubuntu5.4", "binary_name": "apparmor-profiles" }, { "binary_version": "2.13.3-7ubuntu5.4", "binary_name": "apparmor-utils" }, { "binary_version": "2.13.3-7ubuntu5.4", "binary_name": "dh-apparmor" }, { "binary_version": "2.13.3-7ubuntu5.4", "binary_name": "libapache2-mod-apparmor" }, { "binary_version": "2.13.3-7ubuntu5.4", "binary_name": "libapache2-mod-apparmor-dbgsym" }, { "binary_version": "2.13.3-7ubuntu5.4", "binary_name": "libapparmor-dev" }, { "binary_version": "2.13.3-7ubuntu5.4", "binary_name": "libapparmor-perl" }, { "binary_version": "2.13.3-7ubuntu5.4", "binary_name": "libapparmor-perl-dbgsym" }, { "binary_version": "2.13.3-7ubuntu5.4", "binary_name": "libapparmor1" }, { "binary_version": "2.13.3-7ubuntu5.4", "binary_name": "libapparmor1-dbgsym" }, { "binary_version": "2.13.3-7ubuntu5.4", "binary_name": "libpam-apparmor" }, { "binary_version": "2.13.3-7ubuntu5.4", "binary_name": "libpam-apparmor-dbgsym" }, { "binary_version": "2.13.3-7ubuntu5.4", "binary_name": "python3-apparmor" }, { "binary_version": "2.13.3-7ubuntu5.4", "binary_name": "python3-libapparmor" }, { "binary_version": "2.13.3-7ubuntu5.4", "binary_name": "python3-libapparmor-dbgsym" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_version": "3.0.4-2ubuntu2.4", "binary_name": "apparmor" }, { "binary_version": "3.0.4-2ubuntu2.4", "binary_name": "apparmor-dbgsym" }, { "binary_version": "3.0.4-2ubuntu2.4", "binary_name": "apparmor-notify" }, { "binary_version": "3.0.4-2ubuntu2.4", "binary_name": "apparmor-profiles" }, { "binary_version": "3.0.4-2ubuntu2.4", "binary_name": "apparmor-utils" }, { "binary_version": "3.0.4-2ubuntu2.4", "binary_name": "dh-apparmor" }, { "binary_version": "3.0.4-2ubuntu2.4", "binary_name": "libapache2-mod-apparmor" }, { "binary_version": "3.0.4-2ubuntu2.4", "binary_name": "libapache2-mod-apparmor-dbgsym" }, { "binary_version": "3.0.4-2ubuntu2.4", "binary_name": "libapparmor-dev" }, { "binary_version": "3.0.4-2ubuntu2.4", "binary_name": "libapparmor1" }, { "binary_version": "3.0.4-2ubuntu2.4", "binary_name": "libapparmor1-dbgsym" }, { "binary_version": "3.0.4-2ubuntu2.4", "binary_name": "libpam-apparmor" }, { "binary_version": "3.0.4-2ubuntu2.4", "binary_name": "libpam-apparmor-dbgsym" }, { "binary_version": "3.0.4-2ubuntu2.4", "binary_name": "python3-apparmor" }, { "binary_version": "3.0.4-2ubuntu2.4", "binary_name": "python3-libapparmor" }, { "binary_version": "3.0.4-2ubuntu2.4", "binary_name": "python3-libapparmor-dbgsym" } ] }