In all versions of AppArmor mount rules are accidentally widened when compiled.
A vulnerability leading to a local privilege escalation was found in apparmor in the Linux kernel. When procpidattrwrite() was changed to use memdupuser apparmor's (interface violating) assumption that the setprocattr buffer was always a single page was violated.
Upstream pull request:
http://marc.info/?l=linux-kernel&m=146793642811929&w=2
Upstream fix:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=30a46a4647fd1df9cf52e43bf467f0d9265096ca
References:
http://seclists.org/oss-sec/2016/q3/30
apparmorparser in the apparmor package before 2.8.95~2430-0ubuntu5.1 in Ubuntu 14.04 allows attackers to bypass AppArmor policies via unspecified vectors, related to a "miscompilation flaw."
The Linux kernel before 2.6.18.8-0.8 in SUSE openSUSE 10.2 does not properly handle failure of an AppArmor changehat system call, which might allow attackers to trigger the unconfining of an apparmored task.