Please sign in to comment.
scm: Require CAP_SYS_ADMIN over the current pidns to spoof pids.
Don't allow spoofing pids over unix domain sockets in the corner cases where a user has created a user namespace but has not yet created a pid namespace. Cc: email@example.com Reported-by: Andy Lutomirski <firstname.lastname@example.org> Signed-off-by: "Eric W. Biederman" <email@example.com>
- Loading branch information...