{"$schema":"https://docs.oasis-open.org/csaf/csaf/v2.1/schema/csaf.json","document":{"category":"csaf_security_advisory","csaf_version":"2.1","title":"Multiple Vulnerabilities in AppArmor AKA CrackArmor","distribution":{"tlp":{"label":"CLEAR"}},"publisher":{"category":"vendor","name":"WatchGuard PSIRT","namespace":"https://www.watchguard.com"},"tracking":{"id":"WGSA-2026-00008","status":"final","version":"9","initial_release_date":"2026-04-01T12:00:00+00:00","current_release_date":"2026-07-28T01:23:15.089888+00:00","revision_history":[{"date":"2026-04-01T12:00:00+00:00","number":"9","summary":"Initial release."}]},"references":[{"summary":"vendor-advisory","url":"https://psirt.watchguard.com/WGSA-2026-00008"},{"summary":"cve","url":"https://www.cve.org/CVERecord?id=CVE-2026-23268"},{"summary":"cve","url":"https://www.cve.org/CVERecord?id=CVE-2026-23269"}],"notes":[{"category":"summary","text":"On 12 March, Qualys Threat Research disclosed multiple vulnerabilities in the Linux Mandatory Access Control (MAC) framework AppArmor, both in the Linux kernel as well as the AppArmor implementation on popular Linux distributions including Ubuntu, Debian and SUSE. A successful attack involving these vulnerabilities could allow a threat actor with access to the local filesystem to escalate their privileges to Root, bypass MAC policies, or execute a Denial of Service against the vulnerable system.\n\nBoth Dimension v2.3 and WebBlockerServer v2.1 run on an effected version of the Ubuntu operating system. While both Dimension and WebBlocker received automated security updates through the built-in unattended upgrades utility, Linux kernel patches are not available through this utility and must instead be manually installed.","title":"Summary"}]},"product_tree":{"branches":[{"category":"vendor","name":"WatchGuard","branches":[{"category":"product_name","name":"Dimension","branches":[{"category":"product_version_range","name":"all versions","product":{"name":"Dimension all versions","product_id":"CSAFPID-d36d565e-228e-4d9a-888a-9be70889d829"}}]}]}]},"vulnerabilities":[{"notes":[{"category":"description","text":"On 12 March, Qualys Threat Research disclosed multiple vulnerabilities in the Linux Mandatory Access Control (MAC) framework AppArmor, both in the Linux kernel as well as the AppArmor implementation on popular Linux distributions including Ubuntu, Debian and SUSE. A successful attack involving these vulnerabilities could allow a threat actor with access to the local filesystem to escalate their privileges to Root, bypass MAC policies, or execute a Denial of Service against the vulnerable system.\n\nBoth Dimension v2.3 and WebBlockerServer v2.1 run on an effected version of the Ubuntu operating system. While both Dimension and WebBlocker received automated security updates through the built-in unattended upgrades utility, Linux kernel patches are not available through this utility and must instead be manually installed.","title":"Summary"}],"product_status":{"known_affected":["CSAFPID-d36d565e-228e-4d9a-888a-9be70889d829"]},"cve":"CVE-2026-23268"},{"notes":[{"category":"description","text":"On 12 March, Qualys Threat Research disclosed multiple vulnerabilities in the Linux Mandatory Access Control (MAC) framework AppArmor, both in the Linux kernel as well as the AppArmor implementation on popular Linux distributions including Ubuntu, Debian and SUSE. A successful attack involving these vulnerabilities could allow a threat actor with access to the local filesystem to escalate their privileges to Root, bypass MAC policies, or execute a Denial of Service against the vulnerable system.\n\nBoth Dimension v2.3 and WebBlockerServer v2.1 run on an effected version of the Ubuntu operating system. While both Dimension and WebBlocker received automated security updates through the built-in unattended upgrades utility, Linux kernel patches are not available through this utility and must instead be manually installed.","title":"Summary"}],"product_status":{"known_affected":["CSAFPID-d36d565e-228e-4d9a-888a-9be70889d829"]},"cve":"CVE-2026-23269"}]}