Skip to content
This repository has been archived by the owner on Oct 13, 2023. It is now read-only.

[18.06] Add /proc/acpi to masked paths #14

Merged

Commits on Jul 6, 2018

  1. Add /proc/acpi to masked paths

    The deafult OCI linux spec in oci/defaults{_linux}.go in Docker/Moby
    from 1.11 to current upstream master does not block /proc/acpi pathnames
    allowing attackers to modify host's hardware like enabling/disabling
    bluetooth or turning up/down keyboard brightness. SELinux prevents all
    of this if enabled.
    
    Signed-off-by: Antonio Murdaca <[email protected]>
    (cherry picked from commit 569b970)
    Signed-off-by: Sebastiaan van Stijn <[email protected]>
    runcom authored and thaJeztah committed Jul 6, 2018
    Configuration menu
    Copy the full SHA
    caf8277 View commit details
    Browse the repository at this point in the history