Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.kernel > #75976
| From | Philippe Cerfon <philcerf@gmail.com> |
|---|---|
| Newsgroups | linux.debian.kernel |
| Subject | Re: Bug#1012547: linux: disable user namespaces per default |
| Date | 2022-07-20 04:30 +0200 |
| Message-ID | <EL7Dj-cwxG-1@gated-at.bofh.it> (permalink) |
| References | <EKSNX-cnD3-7@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On Tue, Jul 19, 2022 at 12:20 PM <mikoxyzzz@gmail.com> wrote: > I'm sorry that you didn't read the actual CVE. Well I did... which is why I haven't written "the next security hole in user ns" but "the next one that have been mitigated if Debian were to ship sane defaults". > Do correct me if I'm wrong, though. In the end of the day it's still yet another root security hole which was exposed for no good reasons, by user names being enabled per default - where the bug originates in, won't really bother any attacker, nor will it make a difference for any compromised system. Regards, Philippe
Back to linux.debian.kernel | Previous | Next — Previous in thread | Find similar | Unroll thread
Re: Bug#1012547: linux: disable user namespaces per default mikoxyzzz@gmail.com - 2022-07-19 12:40 +0200 Re: Bug#1012547: linux: disable user namespaces per default Philippe Cerfon <philcerf@gmail.com> - 2022-07-20 04:30 +0200
csiph-web