#Apparmor
AppArmor out, SELinux in for openSUSE Tumbleweed.
openSUSE Tumbleweed Ditches AppArmor for SELinux
openSUSE Tumbleweed has changed its default mandatory access control (MAC) system.
news.itsfoss.com
February 15, 2025 at 4:00 AM
A vulnerability in the AppArmor Linux kernel security module can allow attackers to bypass kernel protections, escalate to root, and break container isolation.

The vulnerability impacts all AppArmor versions since 2017.

blog.qualys.com/vulnerabilit...
CrackArmor: Critical AppArmor Flaws Enable Local Privilege Escalation to Root | Qualys
Qualys TRU has discovered confused deputy vulnerabilities in AppArmor (named “CrackArmor”) that allow unprivileged users to bypass kernel protections, escalate to root, and break container isolation. ...
blog.qualys.com
March 14, 2026 at 10:06 PM
openSUSE Replaces AppArmor with SELinux on New Tumbleweed Installations 9to5linux.com/opensuse-rep...

#Linux #OpenSource
openSUSE Replaces AppArmor with SELinux on New Tumbleweed Installations - 9to5Linux
openSUSE Linux adopts SELinux as the default mandatory access control (MAC) system on new openSUSE Tumbleweed installations.
9to5linux.com
February 15, 2025 at 7:41 PM
Die Rolling-Release-Linux-Distribution openSUSE Tumbleweed wechselt bei der Zugriffskontrolle von AppArmor auf SELinux. #Linux
openSUSE Tumbleweed wechselt von AppArmor zu SELinux
Die Rolling-Release-Linux-Distribution openSUSE Tumbleweed wechselt bei der Zugriffskontrolle von AppArmor auf SELinux.
www.heise.de
February 18, 2025 at 1:04 PM
apparmor is cool until its not. i'm looking at you "resolv.conf"
January 7, 2025 at 8:49 PM
AppArmor For Linux 6.17 Set To Introduce AF_UNIX Mediation, Other Improvements - https://www.phoronix.com/news/Linux-6.17-AppArmor
AppArmor For Linux 6.17 Set To Introduce AF_UNIX Mediation, Other Improvements
Canonical engineer John Johansen sent out the AppArmor pull request today for the Linux 6.17 merge window that is heavy on changes for this Linux kernel security module...
www.phoronix.com
August 4, 2025 at 12:58 PM
AppArmor 5.0 porta sicurezza Linux a un nuovo livello con policy più flessibili 🔐 #Linux #Security #AppArmor #OpenSource
AppArmor 5.0 migliora la sicurezza su Linux con policy più avanzate
AppArmor 5.0 introduce nuove policy, miglioramenti sicurezza e gestione avanzata per sistemi Linux moderni.
www.linuxeasy.org
April 25, 2026 at 8:16 AM
Unprivileged users could exploit AppArmor bugs to gain root access
Unprivileged users could exploit AppArmor bugs to gain root access
Nine CrackArmor flaws in Linux AppArmor let unprivileged users bypass protections, gain root privileges, and weaken container isolation
securityaffairs.com
March 16, 2026 at 10:06 AM
> Setting up libapparmor1:amd64 (4.0.1really4.0.1-0ubuntu0.24.04.8)…

Did `apparmor` get caught faking their version numbers or something..

#linux
September 25, 2026 at 5:44 AM
Ubuntu's AppArmor Hit By Several Security Issues - Can Yield Local Privilege Escalation - https://www.phoronix.com/news/Ubuntu-AppArmor-Security-Issues
Ubuntu's AppArmor Hit By Several Security Issues - Can Yield Local Privilege Escalation
The AppArmor Linux kernel security module used notably by Ubuntu Linux and currently maintained by Canonical has been affected by several vulnerabilities made public today...
www.phoronix.com
March 13, 2026 at 12:34 AM
The latest Woodpecker CI release introduces custom AppArmor profiles for the Docker backend, stronger security defaults, and improved Kubernetes handling.
linuxiac.com/woodpecker-c...

#OpenSource #DevOps
Woodpecker CI 3.17 Adds AppArmor Support for Docker Pipelines
The latest Woodpecker CI release introduces custom AppArmor profiles for the Docker backend, stronger security defaults, and improved Kubernetes handling.
linuxiac.com
August 2, 2026 at 9:44 AM
Big Change in #Tumbleweed! Starting with snapshot 20250211, #SELinux will be the default Mandatory Access Control (MAC) system in enforcing mode! Users can still opt for AppArmor during installation. Read more about it! #openSUSE lists.opensuse.org/archives/lis...
February 13, 2025 at 6:31 AM
Confused about how runAsNonRoot, capabilities, seccomp, and AppArmor relate to each other in Kubernetes?

Our new article shows exactly how each SecurityContext field maps to Linux syscalls and kernel

Finally understand what you're actually configuring: https://learnkube.com/security-contexts
August 11, 2025 at 12:31 PM
Canonical is funding research into automated C-to-Rust translation, with AppArmor and snap-confine serving as real-world case studies.
linuxiac.com/canonical-ba...

#OpenSource #Canonical #RustLang
Canonical Backs New Project to Translate Large C Codebases Into Safe Rust
Canonical is funding research into automated C-to-Rust translation, with AppArmor and snap-confine serving as real-world case studies.
linuxiac.com
August 20, 2026 at 7:40 AM
By default, Kubernetes containers run as root (UID 0). If compromised, this increases the risk of privilege escalation to the host

Our new article explains how SecurityContext actually works - from kernel primitives to practical hardening

https://learnkube.com/security-contexts
August 11, 2025 at 12:36 PM
Using my Transmission server for the first time in ages, appears AppArmor is now enabled and was breaking the daemon. Had to modify the AppArmor profile so that it can read from the place I installed TrguiNG and can read/write to the NFS export where I cram downloads.
February 19, 2026 at 3:54 AM
my silly little fedi bot
March 15, 2025 at 2:12 PM
CrackArmor : neuf vulnérabilités ont été découvertes dans AppArmor remontant au noyau Linux 4.11 (2017) et pourraient affecter plus de 12,6 millions de systèmes. (z)

👉
CrackArmor: Critical AppArmor Flaws Enable Local Privilege Escalation to Root | Qualys
Qualys TRU has discovered confused deputy vulnerabilities in AppArmor (named “CrackArmor”) that allow unprivileged users to bypass kernel protections, escalate to root, and break container isolation. The flaw has existed since 2010, and compromises 20 million+ systems globally. Immediate kernel patching is recommended to neutralize these vulnerabilities.
blog.qualys.com
March 15, 2026 at 6:30 PM
It's time to try out OpenSUSE Tumbleweed as the main OS. It's a pity both Arch and NixOS don't have any support for selinux and apparmor is mehish.
June 1, 2025 at 12:42 PM