Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.kernel > #75971 > unrolled thread
| Started by | mikoxyzzz@gmail.com |
|---|---|
| First post | 2022-07-19 12:40 +0200 |
| Last post | 2022-07-20 04:30 +0200 |
| Articles | 2 — 2 participants |
Back to article view | Back to linux.debian.kernel
Re: Bug#1012547: linux: disable user namespaces per default mikoxyzzz@gmail.com - 2022-07-19 12:40 +0200
Re: Bug#1012547: linux: disable user namespaces per default Philippe Cerfon <philcerf@gmail.com> - 2022-07-20 04:30 +0200
| From | mikoxyzzz@gmail.com |
|---|---|
| Date | 2022-07-19 12:40 +0200 |
| Subject | Re: Bug#1012547: linux: disable user namespaces per default |
| Message-ID | <EKSNX-cnD3-7@gated-at.bofh.it> |
On Tue, 5 Jul 2022 at 16:22 Philippe Cerfon <philcerf@gmail.com> wrote: > Say welcome to CVE-2022-32250, the next root security hole which would apparently have been mitigated if Debian were to ship sane defaults. I'm sorry that you didn't read the actual CVE. This wasn't a bug with user namespaces, but rather a bug in netfilter that was exploitable through user namespaces. Of course, this wouldn't really have been exploitable had user namespaces since root using an exploit to elevate its privileges to root is... silly. The bug would've still existed without user namespaces, which is still bad, it just would've been pointless. It's pretty funny, actually; from what I'm able to undertstand, most, if not all the CVEs you listed in your original report weren't really bugs with user namespaces *at all*, they were really just bugs in components *around* user namespaces. Instead, how about we disable netfilter et al. for being buggy? ;) I really don't think the morale of the story here is "user namespaces are dangerous", but rather "code in Linux tends to be buggy and should be fixed", and I don't see why user namespaces should be disabled when it's other components that are buggy dangerous. Do correct me if I'm wrong, though. -- ~miko
[toc] | [next] | [standalone]
| From | Philippe Cerfon <philcerf@gmail.com> |
|---|---|
| Date | 2022-07-20 04:30 +0200 |
| Message-ID | <EL7Dj-cwxG-1@gated-at.bofh.it> |
| In reply to | #75971 |
On Tue, Jul 19, 2022 at 12:20 PM <mikoxyzzz@gmail.com> wrote: > I'm sorry that you didn't read the actual CVE. Well I did... which is why I haven't written "the next security hole in user ns" but "the next one that have been mitigated if Debian were to ship sane defaults". > Do correct me if I'm wrong, though. In the end of the day it's still yet another root security hole which was exposed for no good reasons, by user names being enabled per default - where the bug originates in, won't really bother any attacker, nor will it make a difference for any compromised system. Regards, Philippe
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.kernel
csiph-web