Jessie Frazelle 4/26/2017

Two Objects not Namespaced by the Linux Kernel

Read Original

This technical blog post details two objects not covered by Linux kernel namespaces: time and the kernel keyring. It explains the security implications for container isolation, why these lack namespacing, and warns against disabling security features like seccomp or adding unnecessary capabilities in container environments.

Two Objects not Namespaced by the Linux Kernel

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser