USN-7035-1: AppArmor vulnerability

Publication date

25 September 2024

Overview

AppArmor restrictions could be bypassed for rules allowing mount operations


Packages

Details

It was discovered that the AppArmor policy compiler incorrectly generated
looser restrictions than expected for rules allowing mount operations. A
local attacker could possibly use this to bypass AppArmor restrictions in
applications where some mount operations were permitted.

It was discovered that the AppArmor policy compiler incorrectly generated
looser restrictions than expected for rules allowing mount operations. A
local attacker could possibly use this to bypass AppArmor restrictions in
applications where some mount operations were permitted.

Update instructions

In general, a standard system update will make all the necessary changes. After this update, applications confined by policies with mount operations restrictions may need to have the rules updated.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
22.04 jammy apparmor –  3.0.4-2ubuntu2.4
20.04 focal apparmor –  2.13.3-7ubuntu5.4

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›