CAP_SYS_ADMIN: the new root
CAP_SYS_ADMIN: the new root
Posted Mar 15, 2012 20:05 UTC (Thu) by bronson (subscriber, #4806)In reply to: CAP_SYS_ADMIN: the new root by ballombe
Parent article: CAP_SYS_ADMIN: the new root
That might help but I'd be afraid that it opens another attack surface. A virtual capability may appear safe, but mapping it to a real capability could cause rather nonobvious holes to appear. Especially if multiple virtual capabilities get mapped into a single real one.
