All of lore.kernel.org
 help / color / mirror / Atom feed
* [kernel-hardening] [PATCH 0/2] sysctl: allow CLONE_NEWUSER to be disabled
@ 2016-01-22 22:39 ` Kees Cook
  0 siblings, 0 replies; 78+ messages in thread
From: Kees Cook @ 2016-01-22 22:39 UTC (permalink / raw)
  To: Andrew Morton
  Cc: Kees Cook, Al Viro, Richard Weinberger, Eric W. Biederman,
	Andy Lutomirski, Robert Święcki, Dmitry Vyukov,
	David Howells, Miklos Szeredi, Kostya Serebryany,
	Alexander Potapenko, Eric Dumazet, Sasha Levin, linux-doc,
	linux-kernel, kernel-hardening

There continues to be unexpected side-effects and security exposures
via CLONE_NEWUSER. For many end-users running distro kernels with
CONFIG_USER_NS enabled, there is no way to disable this feature when
desired. As such, this creates a sysctl to restrict CLONE_NEWUSER so
admins not running containers or Chrome can avoid the risks of this
feature.

-Kees

^ permalink raw reply	[flat|nested] 78+ messages in thread

end of thread, other threads:[~2016-01-28 14:41 UTC | newest]

Thread overview: 78+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2016-01-22 22:39 [kernel-hardening] [PATCH 0/2] sysctl: allow CLONE_NEWUSER to be disabled Kees Cook
2016-01-22 22:39 ` Kees Cook
2016-01-22 22:39 ` [kernel-hardening] [PATCH 1/2] sysctl: expand use of proc_dointvec_minmax_sysadmin Kees Cook
2016-01-22 22:39   ` Kees Cook
2016-01-23  3:10   ` [kernel-hardening] " Eric W. Biederman
2016-01-23  3:10     ` Eric W. Biederman
2016-01-23 22:25     ` [kernel-hardening] " Jann Horn
2016-01-24  1:20       ` Eric W. Biederman
2016-01-24  1:43         ` Al Viro
2016-01-24  1:56           ` Jann Horn
2016-01-24  6:02             ` Eric W. Biederman
2016-01-24  6:32               ` Jann Horn
2016-01-24  6:44                 ` Eric W. Biederman
2016-01-22 22:39 ` [kernel-hardening] [PATCH 2/2] sysctl: allow CLONE_NEWUSER to be disabled Kees Cook
2016-01-22 22:39   ` Kees Cook
2016-01-22 22:47   ` [kernel-hardening] " Robert Święcki
2016-01-22 22:47     ` Robert Święcki
2016-01-22 22:50     ` [kernel-hardening] " Kees Cook
2016-01-22 22:50       ` Kees Cook
2016-01-22 22:55       ` [kernel-hardening] " Robert Święcki
2016-01-22 22:55         ` Robert Święcki
2016-01-22 23:00         ` [kernel-hardening] " Kees Cook
2016-01-22 23:00           ` Kees Cook
2016-01-23  0:44           ` [kernel-hardening] " Serge Hallyn
2016-01-23  0:44             ` Serge Hallyn
2016-01-23  0:44           ` [kernel-hardening] " Serge Hallyn
2016-01-23  0:44             ` Serge Hallyn
2016-01-23  0:59           ` [kernel-hardening] " Ben Hutchings
2016-01-24 20:59             ` Kees Cook
2016-01-24 22:20               ` Andy Lutomirski
2016-01-25 18:51                 ` Kees Cook
2016-01-22 22:49 ` [kernel-hardening] Re: [PATCH 0/2] " Richard Weinberger
2016-01-22 22:49   ` Richard Weinberger
2016-01-23  3:02 ` [kernel-hardening] " Eric W. Biederman
2016-01-23  3:02   ` Eric W. Biederman
2016-01-24 20:57   ` [kernel-hardening] " Kees Cook
2016-01-24 20:57     ` Kees Cook
2016-01-26  7:38     ` [kernel-hardening] " Serge Hallyn
2016-01-24 22:22   ` Andy Lutomirski
2016-01-24 22:22     ` Andy Lutomirski
2016-01-25 18:51     ` [kernel-hardening] " Kees Cook
2016-01-25 18:51       ` Kees Cook
2016-01-25 18:53       ` [kernel-hardening] " Andy Lutomirski
2016-01-25 18:53         ` Andy Lutomirski
2016-01-25 18:56         ` [kernel-hardening] " Kees Cook
2016-01-25 18:56           ` Kees Cook
2016-01-25 19:33           ` [kernel-hardening] " Eric W. Biederman
2016-01-25 19:33             ` Eric W. Biederman
2016-01-25 22:34             ` [kernel-hardening] " Kees Cook
2016-01-25 22:34               ` Kees Cook
2016-01-25 23:33               ` [kernel-hardening] " Andy Lutomirski
2016-01-25 23:33                 ` Andy Lutomirski
2016-01-26  2:27               ` [kernel-hardening] " Daniel Micay
2016-01-26  4:57               ` Eric W. Biederman
2016-01-26  4:57                 ` Eric W. Biederman
2016-01-26 14:38                 ` [kernel-hardening] " Josh Boyer
2016-01-26 14:38                   ` Josh Boyer
2016-01-26 14:46                   ` [kernel-hardening] " Austin S. Hemmelgarn
2016-01-26 14:46                     ` Austin S. Hemmelgarn
2016-01-26 14:56                     ` [kernel-hardening] " Josh Boyer
2016-01-26 14:56                       ` Josh Boyer
2016-01-26 17:20                       ` [kernel-hardening] " Serge Hallyn
2016-01-26 19:56                         ` Josh Boyer
2016-01-26 20:11                           ` Austin S. Hemmelgarn
2016-01-26 17:15                   ` Serge Hallyn
2016-01-26 18:09                     ` Austin S. Hemmelgarn
2016-01-26 18:27                       ` Andy Lutomirski
2016-01-26 18:45                         ` Austin S. Hemmelgarn
2016-01-26 23:15                         ` Kees Cook
2016-01-26 23:13                     ` Kees Cook
2016-01-27 10:27                       ` Eric W. Biederman
2016-01-27 12:32                         ` Austin S. Hemmelgarn
2016-01-28 14:41                         ` Robert Święcki
2016-01-26 23:47                     ` Josh Boyer
2016-01-26 16:37                 ` Kees Cook
2016-01-26 16:37                   ` Kees Cook
2016-01-28  8:56                 ` [kernel-hardening] " Serge E. Hallyn
2016-01-28 12:53                   ` Austin S. Hemmelgarn

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.