Workaround: remount /proc nosuid,noexec
Posted Jul 16, 2006 9:43 UTC (Sun) by
Duncan (guest, #6647)
In reply to:
Lots more kernel releases by NightMonkey
Parent article:
Lots more kernel releases
On the Gentoo-devel list, which I follow as I run Gentoo and want to get a
heads-up on things coming down the pike, one of the kernel guys said it
wouldn't affect anyone who has /proc mounted nosuid,noexec. A bit of
testing later and they hadn't found any reason /not/ to do so (there was
speculation about a couple things but it turned out they worked fine
anyway), and I've been running that way for several hours, now, tho I did
update the kernel and it happened to be convenient to reboot at the time
so I did.
For anyone depending on the local security, I'd still recommend
double-checking it as I don't know enough about it to verify it myself,
but doing a /proc remount nosuid,noexec might be a useful workaround for
those who find it inconvenient to reboot ATM. That's how I have fstab
configured to (re)mount it, now, as it seems to make sense in any case,
and Gentoo will probably be making that the default in the next
baselayout, as well.
Duncan
(
Log in to post comments)