Hacker News new | past | comments | ask | show | jobs | submit | nervous's comments login

tl;dr The Sylabs team recently discovered an exploit vector to all container runtimes, that allows a malicious user to gain additional privileges within a container on hosts running kernels that do not support the PR_SET_NO_NEW_PRIVS feature.

Singularity is not the only container platform affected; this vulnerability can be exploited using any container runtime on a vulnerable kernel.


this opens a new era in the car-sharing business!


Hint: Australia is not US


Consider applying for YC's W25 batch! Applications are open till Nov 12.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: