3 ms·
I read both links, and the "isolation" provided by cgroups alone will not prevent exploitation of this bug (or any other, for that matter).
by eeZi 11y ago
I read both links, and the "isolation" provided by cgroups alone will not prevent exploitation of this bug (or any other, for that matter).
- rwmj 11y agoYou can flat out wrong about this, as you have been in your other answers. I am an upstream libvirt committer so I do know a fair bit about what libvirt can do. The fact is that the isolation of cgroups will prevent various denial of service bugs, and also access to non-whitelisted devices. It is nowhere near as comprehensive as SELinux isolation, as I clearly said way up there in my initial response -- which is also the reason why when you use Docker on RHEL, most of the security comes from the additional SELinux protections Red Hat have added.
- eeZi 11y agoI agree with you that cgroups protect against denial of service attacks, and that the device whitelist provides some additional security (I actually did not know about the latter, so thanks! TIL). Thinking about it, if you exclusively use block devices for storage, this is a lot better than I expected. But still, this is nowhere from a "a least-privilege container for each VM" as you suggested. (I'm a heavy libvirt user myself - thank you for your work on it!)