3 ms·
I've also written a smallish blogpost about this CVE. I'm a LX{C,D} maintainer and I've worked with Aleksa the runC maintainer together on a fix for this CVE: h
by brauner 8y ago
I've also written a smallish blogpost about this CVE. I'm a LX{C,D} maintainer and I've worked with Aleksa the runC maintainer together on a fix for this CVE:
https://brauner.github.io/2019/02/12/privileged-containers.html https://brauner.github.io/2019/02/12/privileged-containers.h...
- arno1 8y agoThank you @brauner for writing this blogpost! IIUC, using Docker's userns-remap would protect against this CVE by making the containers run unprivileged (container's id 0 != host's id 0) and should generally be the industry's best practice.