Menu

#Seccomp

6 posts

Feed·
6 of 6 posts
📰
0

Software sandboxing: The basics

blog.emilua.org·19 days ago
#FCsTaRku

// These policies are heavily influenced by Docker's default profile. Further // customization done on top: // // - Avoid syscalls that need root anyway.…

15s
Read More
We tested Copy Fail in Kubernetes: RuntimeDefault seccomp still allowed AF_ALG from pods
📰
0

We tested Copy Fail in Kubernetes: RuntimeDefault seccomp still allowed AF_ALG from pods

Copy Fail is the recent Linux kernel issue involving `AF_ALG`, the kernel crypto socket interface, and page-cache-backed file data. The short version: it is kernel attack surface reachable through a syscall path, not an application dependency inside an…

15s
Read More
GHSA-VJGJ-42F6-7997: GHSA-vjgj-42f6-7997: Protection Mechanism Failure via Incomplete Seccomp Sandbox in Netfoil
🖼️
0

GHSA-VJGJ-42F6-7997: GHSA-vjgj-42f6-7997: Protection Mechanism Failure via Incomplete Seccomp Sandbox in Netfoil

DEV Community·CVE Reports·5 months ago
#x1TVqmmM
#security#cve#cybersecurity#ghsa#netfoil#vjgj

From Dev.to - security: GHSA-VJGJ-42F6-7997: GHSA-vjgj-42f6-7997: Protection Mechanism Failure via Incomplete Seccomp Sandbox in Netfoil

15s
Read More