Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #68589

Bug#898446: Please reconsider enabling the user namespaces by default

From Antoine Beaupré <anarcat@debian.org>
Newsgroups linux.debian.bugs.dist, linux.debian.kernel
Subject Bug#898446: Please reconsider enabling the user namespaces by default
Date 2020-11-17 17:30 +0100
Message-ID <Bcc1I-2gs-7@gated-at.bofh.it> (permalink)
References (7 earlier) <B22Gl-2Ox-3@gated-at.bofh.it> <vOlh7-2Ek-5@gated-at.bofh.it> <B2PQK-6ZD-13@gated-at.bofh.it> <vOlh7-2Ek-5@gated-at.bofh.it> <B2PQK-6ZD-13@gated-at.bofh.it>
Organization Debian

Cross-posted to 2 groups.

Show all headers | View raw


On 2020-10-22 22:55:33, Salvatore Bonaccorso wrote:
> Hi,
>
> On Tue, Oct 20, 2020 at 05:21:24PM +0100, Simon McVittie wrote:
>> On Thu, 16 Apr 2020 at 03:09:25 +0100, Ben Hutchings wrote:
>> > I don't think we should keep patching in
>> > kernel.unprivileged_userns_clone forever, so the documented way to
>> > disable user namespaces should be setting user.max_user_namespaces to
>> > 0.  But then there's no good way to have a drop-in file that changes
>> > back to the upstream default, because that's dependent on system memory
>> > size.
>> > 
>> > So I think we should do something like this:
>> > 
>> > * Document user.max_user_namespaces in procps's shipped
>> >   /etc/sysctl.conf
>> > * Set kernel.unprivileged_userns_clone to 1 by default, and deprecate
>> >   it (log a warning if it's changed)
>> > * Document the change in bullseye release notes
>> 
>> Is this something you intend to do before bullseye, or is it now going
>> to be after bullseye?
>> 
>> If this is intended to happen before bullseye, I'd like enough time
>> before the freeze to put an as-graceful-as-possible transition in place
>> in the bubblewrap package.
>> 
>> (I'm not sure what form that transition should take - suggestions welcome!
>> Ideally I'd like bubblewrap to be setuid root if and only if we are still
>> using a kernel where it needs to be.)
>
> TBH, I think not having it enabled by default until now saved us a
> couple of time from needing to release urgent fixes. It is more a gut
> feeling and might not have enough weight: but having it still disabled
> in bullseye by default we would be still better of from security
> releases/DSA's perspectives.

Could we get a little more hard data about the attack vectors here? I
totally trust the security team's "gut feeling" on this, but it would be
great to be able to evaluate more concretely what we're talking about
here.

Local root privilege escalation, basically? Can we get a sense of what
those vulerabilities are, say with some example CVEs?

I'm asking because my main concern with security these days is with the
web browser. It's this huge gaping hole: every measure we can take to
sandbox that thing is become more and more critical, so I wonder if the
our tradeoff's evaluation is well adjusted here, especially considering
a lot of user_ns consumers are bypassing those restrictions by running
as root anyways...

It seems that, in those cases, we're getting the worst of both worlds...

a.
-- 
It is a miracle that curiosity survives formal education
                        - Albert Einstein

Back to linux.debian.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Bug#898446: Please reconsider enabling the user namespaces by default Laurent Bigonville <bigon@debian.org> - 2018-05-11 20:50 +0200
  Processed: Re: Bug#898446: Please reconsider enabling the user  namespaces by default "Debian Bug Tracking System" <owner@bugs.debian.org> - 2018-05-13 01:40 +0200
  Bug#898446: Please reconsider enabling the user namespaces by default Ben Hutchings <ben@decadent.org.uk> - 2018-05-13 01:40 +0200
    Bug#898446: Please reconsider enabling the user namespaces by default Frederik Himpe <frederik@frehi.be> - 2018-05-13 19:40 +0200
      Bug#898446: Please reconsider enabling the user namespaces by default Ben Hutchings <ben@decadent.org.uk> - 2018-05-14 04:50 +0200
    Bug#898446: Please reconsider enabling the user namespaces by default Moritz Mühlenhoff <jmm@inutil.org> - 2018-05-13 23:10 +0200
      Bug#898446: Please reconsider enabling the user namespaces by default Simon McVittie <smcv@debian.org> - 2020-03-30 12:10 +0200
        Bug#898446: Please reconsider enabling the user namespaces by default Moritz Mühlenhoff <jmm@inutil.org> - 2020-03-30 14:30 +0200
        Bug#898446: Please reconsider enabling the user namespaces by default Ben Hutchings <ben@decadent.org.uk> - 2020-04-15 04:00 +0200
          Bug#898446: Please reconsider enabling the user namespaces by default Simon McVittie <smcv@debian.org> - 2020-04-15 09:40 +0200
            Bug#898446: Please reconsider enabling the user namespaces by default Ben Hutchings <ben@decadent.org.uk> - 2020-04-16 04:20 +0200
              Bug#898446: Please reconsider enabling the user namespaces by default Simon McVittie <smcv@debian.org> - 2020-10-20 18:30 +0200
                Bug#898446: Please reconsider enabling the user namespaces by default Salvatore Bonaccorso <carnil@debian.org> - 2020-10-22 23:00 +0200
                Bug#898446: Please reconsider enabling the user namespaces by default Moritz Muehlenhoff <jmm@inutil.org> - 2020-10-22 23:10 +0200
                Bug#898446: Please reconsider enabling the user namespaces by default Bastian Blank <waldi@debian.org> - 2020-10-23 09:00 +0200
                Bug#898446: Please reconsider enabling the user namespaces by default Antoine Beaupré <anarcat@debian.org> - 2020-11-17 17:30 +0100
                Bug#898446: Please reconsider enabling the user namespaces by default Ben Hutchings <ben@decadent.org.uk> - 2020-11-17 19:00 +0100
                Bug#898446: Please reconsider enabling the user namespaces by default Ben Hutchings <ben@decadent.org.uk> - 2020-12-13 17:40 +0100
                Bug#898446: Please reconsider enabling the user namespaces by default Ben Hutchings <ben@decadent.org.uk> - 2020-10-24 03:30 +0200
    Bug#898446: Please reconsider enabling the user namespaces by default Laurent Bigonville <bigon@debian.org> - 2018-05-14 07:30 +0200
  Processed: Re: Bug#898446: Please reconsider enabling the user  namespaces by default "Debian Bug Tracking System" <owner@bugs.debian.org> - 2018-05-14 04:50 +0200
  Bug#898446: (no subject) Nikolas Nyby <nikolas@gnu.org> - 2019-03-06 15:50 +0100
  Bug#898446: Please reconsider enabling the user namespaces by default Jordan Glover <Golden_Miller83@protonmail.ch> - 2020-10-23 17:30 +0200
  Bug#898446: marked as done (Please reconsider enabling the user  namespaces by default) "Debian Bug Tracking System" <owner@bugs.debian.org> - 2020-12-17 13:10 +0100

csiph-web