|
|
Log in / Subscribe / Register

Anatomy of a user namespaces vulnerability

Anatomy of a user namespaces vulnerability

Posted Jul 2, 2017 19:34 UTC (Sun) by Dippynark (guest, #117191)
Parent article: Anatomy of a user namespaces vulnerability

Excellent article, very useful for cementing my understanding of namespaces.

I am bit confused about one aspect of the fix; one part of the fix is 'make CLONE_NEWUSER automatically imply CLONE_FS in the unshare() system call'. In this case, couldn't the child in the description of the exploit simply fork and then the grandchild could call unshare(CLONE_NEWUSER) (which would be the same as unshare(CLONE_NEWUSER | CLONE_FS) according to the fix), putting it back into the same environment as described in the article?


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds