Posted Mar 16, 2012 5:40 UTC (Fri) by Arach (subscriber, #58847)
Parent article: CAP_SYS_ADMIN: the new root
There's another problem that should be considered in this context. The kernel code restricted with capabilities might be written with relaxed sense of security and/or without due audit, because of a false assumption that capable processes are more trusted than unprivileged ones.