Product
high
advisory
Linux AppArmor Bypass via aa-exec (CVE-2026-46331)
1 rule 1 TTP 1 CVE 3 IOCsAdversaries can exploit CVE-2026-46331 to bypass AppArmor and unprivileged user namespace restrictions on Linux systems by abusing the `aa-exec` utility with `trinity`, `chrome`, or `flatpak` AppArmor profiles, leading to privilege escalation when the `aa-exec` binary itself is executed from a non-standard path.
AppArmor +8
linux
privilege-escalation
cve
endpoint
1r
1t
1c
3i
updated
medium
advisory
AppArmor Policy Interface Tampering
3 rules 1 TTPDetection of unauthorized access to AppArmor kernel policy control interfaces, specifically the `.load`, `.replace`, or `.remove` files, indicating potential defense evasion or policy tampering on Linux systems.
AppArmor
defense-evasion
linux
3r
1t
medium
advisory
AppArmor Profile Compilation via apparmor_parser
2 rules 1 TTPAdversaries may abuse `apparmor_parser` to compile custom AppArmor profiles, potentially weakening security controls and facilitating privilege escalation on Linux systems.
AppArmor
defense-evasion
linux
2r
1t