Anatomy of a user namespaces vulnerability
Anatomy of a user namespaces vulnerability
Posted Mar 21, 2013 0:13 UTC (Thu) by butlerm (subscriber, #13312)Parent article: Anatomy of a user namespaces vulnerability
It is hard to see how most of that could possibly be useful in such a combination, and some of it looks positively dangerous. And if that is the case, wouldn't the conservative option be to disable the combination of CLONE_NEWUSER with everything that isn't recognized as necessary and/or useful?
Perhaps it might also be worthwhile to consider renaming the CLONE_xxx options to clearly indicate which options actually clone things, which ones share things, and which ones create new things. With aliases for backward compatibility of course.
