9 ms·
on https://bugzilla.redhat.com/show_bug.cgi?id=2196105 https://bugzilla.redhat.com/show_bug.cgi?id=2196105 a comment suggests that it might only be possible if
by 0x006A 3y ago
on https://bugzilla.redhat.com/show_bug.cgi?id=2196105 https://bugzilla.redhat.com/show_bug.cgi?id=2196105 a comment suggests that it might only be possible if you have "unprivileged user namespaces" enabled
- pizzalife 3y ago>a comment suggests that it might only be possible if you have "unprivileged user namespaces" enabled Which is the default on Ubuntu.
- chlorion 3y agoIt's the default on pretty much any modern Linux system!
- klooney 3y agoFrom 2016- https://lwn.net/Articles/673597/ https://lwn.net/Articles/673597/ Andy Lutomirski described some concerns of his own: > I consider the ability to use CLONE_NEWUSER to acquire CAP_NET_ADMIN over /any/ network namespace and to thus access the network configuration API to be a huge risk. For example, unprivileged users can program iptables. I'll eat my hat if there are no privilege escalations in there.
- withinboredom 3y agoI hope he hasn't been eating his hat all these years. I hear that isn't good for the digestive system... /s