On 11-08-15 14:41, Thompson, David wrote:
> 
> Fixed in commit bc459b6, which skips the tests if /proc/self/setgroups
> does not exist, rather than allowing a system with a vulnerable kernel
> create containers with a new user namespace.

Thanks for the fast response and fix!

> 
> I would like to note that you should update your kernel as soon as
> possible, as the lack of /proc/self/setgroups means that you are
> running a kernel with a known security vulnerability.  The fix was
> introduced in Linux 3.19, but backported to many older kernels,
> including 3.13.

Thanks for the advice, I have updated my kernel.



Reply via email to