LWN.net Logo

Surrender?

Surrender?

Posted Jun 1, 2012 18:07 UTC (Fri) by Cyberax (✭ supporter ✭, #52523)
In reply to: Surrender? by jmorris42
Parent article: Re: /tmp on multi-FS set-ups, or: block users from using /tmp?

That's pretty much true. Normal Linux user accounts can become root or kernel easily - local kernel exploits are published about once a year and probably quite a number of unpublished exploits exist.

So yes, your only hope is to contain untrusted code inside of a sandbox. And even that is non-trivial - just ask Google.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds