5 ms·
Selinux should block the VENOM vulnerability in Qemu: http://danwalsh.livejournal.com/71489.html http://danwalsh.livejournal.com/71489.html See also http://www.
by baghira 11y ago
Selinux should block the VENOM vulnerability in Qemu: http://danwalsh.livejournal.com/71489.html http://danwalsh.livejournal.com/71489.html
See also http://www.selinuxproject.org/page/SVirt http://www.selinuxproject.org/page/SVirt
Keep in mind that Grsec (which is definitely underdeployed in the linux community) is compatible with LSM such as SElinx and AppArmor, so you do not have to choose (you'll take a performance hit, though).
- benmmurphy 11y agoDo you know why people prefer to use labels in SELinux to isolate different Qemu instances rather than use different UIDs? Is it just a matter of convenience?
- mjg59 11y agoIt's easy to grant a process the privilege to transition to isolated SELiniux contexts, but it's difficult to grant a process the privilege to transition to a limited range of UIDs. Doing it with SELinux also makes it easier to provide additional restrictions - there's a lot of files and device nodes that have to be a+r for normal processes, but which don't need to be available to code running in containers. Using SELinux allows you to prevent the container processes from having access to anything other than the files inside their namespace without needing to entirely refactor the permissions in the host.