Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1315330
| From | Robert Święcki <robert@swiecki.net> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: fs: sandboxed process brings host down |
| Date | 2016-01-22 23:40 +0100 |
| Message-ID | <qTSx6-20U-47@gated-at.bofh.it> (permalink) |
| References | <qTR7Y-19M-9@gated-at.bofh.it> <qTRrk-1iu-1@gated-at.bofh.it> <qTRB1-1oj-39@gated-at.bofh.it> <qTRUm-1vG-3@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
2016-01-22 22:55 GMT+01:00 Al Viro <viro@zeniv.linux.org.uk>: > On Fri, Jan 22, 2016 at 10:38:40PM +0100, Dmitry Vyukov wrote: > >> My 2GB VM dies at around just 10-th iteration, is it normal? >> Each iteration consumes several hundreds of megs of kernel memory. And >> there seems to be exponential slowdown at around 5-th iteration. >> I understand that there can be lots of forms of a local DoS. But there >> seems to be something pathological about this particular one. And it >> happens only with sandboxing that is meant to reduce DoS >> possibilities... > > Sandboxing == giving attacker to do mount without being root. I was discussing this initially with Dmitry and maybe I explained it initially a bit incorrectly. I did not mean to suggest that using CLONE_NEWUSER alone is a form of sandboxing. But rather, that when used correctly (with dropping capabilities, rlimits and seccomp-bpf filters) it could constitute a form of sandboxing. What I suggested was to use CLONE_NEWUSER and friends to test the new attack surface, which is enabled by using CLONE_NEW*. For regular users the syscall(__NR_mount) returns early with EPERM, but when CLONE_NEW* are used, a new, big attack surface opens up, reachable from a level of a unprivileged user. So, I guess, it's not about sandboxing but the newly reachable attack surface. -- Robert Święcki
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Re: fs: sandboxed process brings host down Al Viro <viro@ZenIV.linux.org.uk> - 2016-01-22 22:30 +0100
Re: fs: sandboxed process brings host down Dmitry Vyukov <dvyukov@google.com> - 2016-01-22 22:40 +0100
Re: fs: sandboxed process brings host down Al Viro <viro@ZenIV.linux.org.uk> - 2016-01-22 23:00 +0100
Re: fs: sandboxed process brings host down Robert Święcki <robert@swiecki.net> - 2016-01-22 23:40 +0100
Re: fs: sandboxed process brings host down Kees Cook <keescook@google.com> - 2016-01-22 22:50 +0100
csiph-web