Hi,

On Thu, 2 Mar 2023, at 04:40, Russell Coker wrote:
> Package: wpasupplicant
> Version: 2:2.10-11
> Severity: normal
> Tags: patch
>
> If you run "systemd-analyze security wpa_supplicant.service" you will see it
> has an exposure score of 9.6, if you add the following settings then it goes
> down to 3.2.  This has been tested in Debian/Testing and Ubuntu 22.04 and
> found to work well.  The only difference between Debian and Ubuntu in this
> regard is that the Debian will SEGV if lchown() is denied so the @privileged
> set of system calls can't be used in SystemCallFilter=~ .  I know you might
> not want to apply this when we are in the process of a release freeze, but I
> would appreciate any feedback you can offer on this now.

Thank you for the suggestion. I’m wondering if there’s some minimal subset of 
these we can apply without risking breaking someone’s usecase?

-- 
Cheers,
  Andrej

Reply via email to