Unprivileged user namespaces...
Unprivileged user namespaces...
Posted Jun 3, 2026 4:11 UTC (Wed) by ebiederm (subscriber, #35028)In reply to: Unprivileged user namespaces... by Lionel_Debroux
Parent article: Seven stable kernels for the first day of June
Disabling them is entirely reasonable if you don't need them.
However don't congratulate yourself too much. In almost all cases I have reviewed the problem case is still exploitable with unprivileged user namespaces disabled. It is just trickier. The mentioned CVE looks like it could be exploitable without being able to create your own mount namespace it would just be trickier.
In a lot of cases what unprivileged user namespaces accomplish in practice is to make it easy enough to exploit a bug that people take the bug seriously and get it fixed.
