Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.kernel > #75971
| From | mikoxyzzz@gmail.com |
|---|---|
| Newsgroups | linux.debian.kernel |
| Subject | Re: Bug#1012547: linux: disable user namespaces per default |
| Date | 2022-07-19 12:40 +0200 |
| Message-ID | <EKSNX-cnD3-7@gated-at.bofh.it> (permalink) |
| Organization | linux.* mail to news gateway |
On Tue, 5 Jul 2022 at 16:22 Philippe Cerfon <philcerf@gmail.com> wrote: > Say welcome to CVE-2022-32250, the next root security hole which would apparently have been mitigated if Debian were to ship sane defaults. I'm sorry that you didn't read the actual CVE. This wasn't a bug with user namespaces, but rather a bug in netfilter that was exploitable through user namespaces. Of course, this wouldn't really have been exploitable had user namespaces since root using an exploit to elevate its privileges to root is... silly. The bug would've still existed without user namespaces, which is still bad, it just would've been pointless. It's pretty funny, actually; from what I'm able to undertstand, most, if not all the CVEs you listed in your original report weren't really bugs with user namespaces *at all*, they were really just bugs in components *around* user namespaces. Instead, how about we disable netfilter et al. for being buggy? ;) I really don't think the morale of the story here is "user namespaces are dangerous", but rather "code in Linux tends to be buggy and should be fixed", and I don't see why user namespaces should be disabled when it's other components that are buggy dangerous. Do correct me if I'm wrong, though. -- ~miko
Back to linux.debian.kernel | Previous | Next — Next in thread | Find similar | Unroll thread
Re: Bug#1012547: linux: disable user namespaces per default mikoxyzzz@gmail.com - 2022-07-19 12:40 +0200 Re: Bug#1012547: linux: disable user namespaces per default Philippe Cerfon <philcerf@gmail.com> - 2022-07-20 04:30 +0200
csiph-web