linneman
labs
building
breaking
observing
content
···
verified
home
/ apparmor
Apparmor
2026.09.02
NetworkManager-l2tp: A Newline to Root
An unprivileged D-Bus call writes a root-parsed VPN config value. One newline, root code execution, confinement escape.
2026.05.13
Two Hops and a Shell on Ubuntu
Ubuntu’s userns AppArmor patch checks a pointer, not a property. Two profile hops chain a confined process to host root.
2026.05.11
Porting Dirty Frag to arm64
On aarch64 the rxrpc path oopses and AppArmor blocks the exploit over SSH. A complain-mode profile transition slips it through.