Re: AUFS security issue - Copying Linux Capabilities using copy_up

2021-09-02 Thread Alon Zahavi

Re: AUFS security issue - Copying Linux Capabilities using copy_up

2021-09-02 Thread hooanon05g
Alon Zahavi: > I understand but think you may consider taking more security measures in > regards to the problem. For example, one way to overcome this issue is to > check if a copy-up-ed file is a capable file, and if it is, strip the > capabilities from it. Another mitigation is to check at the