Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #75971 > unrolled thread

Re: Bug#1012547: linux: disable user namespaces per default

Started bymikoxyzzz@gmail.com
First post2022-07-19 12:40 +0200
Last post2022-07-20 04:30 +0200
Articles 2 — 2 participants

Back to article view | Back to linux.debian.kernel


Contents

  Re: Bug#1012547: linux: disable user namespaces per default mikoxyzzz@gmail.com - 2022-07-19 12:40 +0200
    Re: Bug#1012547: linux: disable user namespaces per default Philippe Cerfon <philcerf@gmail.com> - 2022-07-20 04:30 +0200

#75971 — Re: Bug#1012547: linux: disable user namespaces per default

Frommikoxyzzz@gmail.com
Date2022-07-19 12:40 +0200
SubjectRe: Bug#1012547: linux: disable user namespaces per default
Message-ID<EKSNX-cnD3-7@gated-at.bofh.it>
On Tue, 5 Jul 2022 at 16:22 Philippe Cerfon <philcerf@gmail.com> wrote:
 > Say welcome to CVE-2022-32250, the next root security hole which 
would
apparently have been mitigated if Debian were to ship sane defaults.

I'm sorry that you didn't read the actual CVE. This wasn't a bug with
user namespaces, but rather a bug in netfilter that was exploitable
through user namespaces. Of course, this wouldn't really have been
exploitable had user namespaces since root using an exploit to elevate
its privileges to root is... silly. The bug would've still existed
without user namespaces, which is still bad, it just would've been
pointless.

It's pretty funny, actually; from what I'm able to undertstand, most,
if not all the CVEs you listed in your original report weren't really
bugs with user namespaces *at all*, they were really just bugs in
components *around* user namespaces. Instead, how about we disable
netfilter et al. for being buggy? ;)

I really don't think the morale of the story here is "user namespaces
are dangerous", but rather "code in Linux tends to be buggy and should 
be
fixed", and I don't see why user namespaces should be disabled when it's
other components that are buggy dangerous.

Do correct me if I'm wrong, though.

--
~miko

[toc] | [next] | [standalone]


#75976

FromPhilippe Cerfon <philcerf@gmail.com>
Date2022-07-20 04:30 +0200
Message-ID<EL7Dj-cwxG-1@gated-at.bofh.it>
In reply to#75971
On Tue, Jul 19, 2022 at 12:20 PM <mikoxyzzz@gmail.com> wrote:
> I'm sorry that you didn't read the actual CVE.

Well I did... which is why I haven't written "the next security hole
in user ns" but "the next one that have been mitigated if Debian were
to ship sane defaults".


> Do correct me if I'm wrong, though.

In the end of the day it's still yet another root security hole which
was exposed for no good reasons, by user names being enabled per
default - where the bug originates in, won't really bother any
attacker, nor will it make a difference for any compromised system.

Regards,
Philippe

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.kernel


csiph-web