Local root vulnerability in snap-confine
Local root vulnerability in snap-confine
Posted Feb 18, 2022 14:57 UTC (Fri) by Wol (subscriber, #4433)In reply to: Local root vulnerability in snap-confine by epa
Parent article: Local root vulnerability in snap-confine
Yup. Don't snapshot your symlinks per process, but make it so the first access caches it - REMEMBERING THE INODE - and any further attempts to access the symlink get the same inode until the cache is actively flushed.
Cheers,
Wol
