On 11-08-15 14:41, Thompson, David wrote: > > Fixed in commit bc459b6, which skips the tests if /proc/self/setgroups > does not exist, rather than allowing a system with a vulnerable kernel > create containers with a new user namespace.
Thanks for the fast response and fix! > > I would like to note that you should update your kernel as soon as > possible, as the lack of /proc/self/setgroups means that you are > running a kernel with a known security vulnerability. The fix was > introduced in Linux 3.19, but backported to many older kernels, > including 3.13. Thanks for the advice, I have updated my kernel.
