Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.kernel > #66655
| From | Moritz Mühlenhoff <jmm@inutil.org> |
|---|---|
| Newsgroups | linux.debian.bugs.dist, linux.debian.kernel |
| Subject | Bug#898446: Please reconsider enabling the user namespaces by default |
| Date | 2020-03-30 14:30 +0200 |
| Message-ID | <zQ1Id-6Qj-1@gated-at.bofh.it> (permalink) |
| References | <vP6pI-7St-9@gated-at.bofh.it> <vOlh7-2Ek-5@gated-at.bofh.it> <zPZwK-5AZ-9@gated-at.bofh.it> <vOlh7-2Ek-5@gated-at.bofh.it> <zPZwK-5AZ-9@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
Cross-posted to 2 groups.
On Mon, Mar 30, 2020 at 10:56:48AM +0100, Simon McVittie wrote:
> On Fri, 11 May 2018 at 20:44:50 +0200, Laurent Bigonville wrote:
> > Firefox (and probably other applications) are using user namespaces these
> > days to enhance the security.
> >
> > Debian is disabling these since 2013, the original patch states it's a
> > short term solution, but we are here 5 years later and they are still
> > disabled.
> >
> > Apparently debian (and ubuntu) and arch are the only distributions
> > disabling the user namespaces.
>
> A cross-distro status update:
>
> - Debian still disables user namespaces by default with our
> /proc/sys/kernel/unprivileged_userns_clone patch.
>
> - Ubuntu now enables user namespaces by default. I think they still apply
> the /proc/sys/kernel/unprivileged_userns_clone patch, but with the
> default flipped?
>
> - Arch Linux now enables user namespaces in their default kernel. There
> is a non-default kernel, "linux-hardened", which applies the same patch
> as Debian.
>
> - Apparently RHEL 7 also disables user namespaces, although instead of
> patching in a new sysctl, they set /proc/sys/user/max_user_namespaces
> to 0 (which is an upstream thing since Linux 4.9).
>
> On Sun, 13 May 2018 at 22:57:56 +0200, Moritz Mühlenhoff wrote:
> > Ben Hutchings wrote:
> > > And this still mitigates a significant fraction of the security issues
> > > found in the kernel.
> >
> > A quite significant fraction; on average this neutralises a root privilege
> > escalation every month or so. This is really not something that we should
> > re-enable any time soon.
>
> Is this still the case, or has the status of user namespaces settled down?
It think we should still keep it disabled for Bullseye, there's still a good
rate of local privilege escalation vulnerabilities in core code with
unpriv usernamespaces. We could enable it after the Bullseye release and
tally security issues enabled by unpriv namespaces and then make a
decision after a year or so.
Cheers,
Moritz
Back to linux.debian.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Bug#898446: Please reconsider enabling the user namespaces by default Laurent Bigonville <bigon@debian.org> - 2018-05-11 20:50 +0200
Processed: Re: Bug#898446: Please reconsider enabling the user namespaces by default "Debian Bug Tracking System" <owner@bugs.debian.org> - 2018-05-13 01:40 +0200
Bug#898446: Please reconsider enabling the user namespaces by default Ben Hutchings <ben@decadent.org.uk> - 2018-05-13 01:40 +0200
Bug#898446: Please reconsider enabling the user namespaces by default Frederik Himpe <frederik@frehi.be> - 2018-05-13 19:40 +0200
Bug#898446: Please reconsider enabling the user namespaces by default Ben Hutchings <ben@decadent.org.uk> - 2018-05-14 04:50 +0200
Bug#898446: Please reconsider enabling the user namespaces by default Moritz Mühlenhoff <jmm@inutil.org> - 2018-05-13 23:10 +0200
Bug#898446: Please reconsider enabling the user namespaces by default Simon McVittie <smcv@debian.org> - 2020-03-30 12:10 +0200
Bug#898446: Please reconsider enabling the user namespaces by default Moritz Mühlenhoff <jmm@inutil.org> - 2020-03-30 14:30 +0200
Bug#898446: Please reconsider enabling the user namespaces by default Ben Hutchings <ben@decadent.org.uk> - 2020-04-15 04:00 +0200
Bug#898446: Please reconsider enabling the user namespaces by default Simon McVittie <smcv@debian.org> - 2020-04-15 09:40 +0200
Bug#898446: Please reconsider enabling the user namespaces by default Ben Hutchings <ben@decadent.org.uk> - 2020-04-16 04:20 +0200
Bug#898446: Please reconsider enabling the user namespaces by default Simon McVittie <smcv@debian.org> - 2020-10-20 18:30 +0200
Bug#898446: Please reconsider enabling the user namespaces by default Salvatore Bonaccorso <carnil@debian.org> - 2020-10-22 23:00 +0200
Bug#898446: Please reconsider enabling the user namespaces by default Moritz Muehlenhoff <jmm@inutil.org> - 2020-10-22 23:10 +0200
Bug#898446: Please reconsider enabling the user namespaces by default Bastian Blank <waldi@debian.org> - 2020-10-23 09:00 +0200
Bug#898446: Please reconsider enabling the user namespaces by default Antoine Beaupré <anarcat@debian.org> - 2020-11-17 17:30 +0100
Bug#898446: Please reconsider enabling the user namespaces by default Ben Hutchings <ben@decadent.org.uk> - 2020-11-17 19:00 +0100
Bug#898446: Please reconsider enabling the user namespaces by default Ben Hutchings <ben@decadent.org.uk> - 2020-12-13 17:40 +0100
Bug#898446: Please reconsider enabling the user namespaces by default Ben Hutchings <ben@decadent.org.uk> - 2020-10-24 03:30 +0200
Bug#898446: Please reconsider enabling the user namespaces by default Laurent Bigonville <bigon@debian.org> - 2018-05-14 07:30 +0200
Processed: Re: Bug#898446: Please reconsider enabling the user namespaces by default "Debian Bug Tracking System" <owner@bugs.debian.org> - 2018-05-14 04:50 +0200
Bug#898446: (no subject) Nikolas Nyby <nikolas@gnu.org> - 2019-03-06 15:50 +0100
Bug#898446: Please reconsider enabling the user namespaces by default Jordan Glover <Golden_Miller83@protonmail.ch> - 2020-10-23 17:30 +0200
Bug#898446: marked as done (Please reconsider enabling the user namespaces by default) "Debian Bug Tracking System" <owner@bugs.debian.org> - 2020-12-17 13:10 +0100
csiph-web