LWN.net Logo

CAP_SYS_ADMIN: the new root

CAP_SYS_ADMIN: the new root

Posted Mar 16, 2012 5:40 UTC (Fri) by Arach (subscriber, #58847)
Parent article: CAP_SYS_ADMIN: the new root

There's another problem that should be considered in this context. The kernel code restricted with capabilities might be written with relaxed sense of security and/or without due audit, because of a false assumption that capable processes are more trusted than unprivileged ones.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds