Skip to content

systemd: Improvements in security configuration#42

Open
nicoonoclaste wants to merge 4 commits into
skeeto:masterfrom
nicoonoclaste:systemd/security
Open

systemd: Improvements in security configuration#42
nicoonoclaste wants to merge 4 commits into
skeeto:masterfrom
nicoonoclaste:systemd/security

Conversation

@nicoonoclaste

Copy link
Copy Markdown
Contributor

Ported the security-related improvements of #40 to the non-templated endlessh.service.

No UNIX sockets, netlink, raw sockets, ...
- Namespaces (esp. user namespaces) have been a big source of
  privilege-escalation vulnerabilities in the past.

- `personality(2)` provides access to complex, legacy emulation code.

- Realtime scheduling can be abused to DoS the host by consuming all
  available CPU time.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant