GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Rich Felker (dalias@hachyderm.io)'s status on Friday, 08-May-2026 09:22:33 JST Rich Felker Rich Felker
    in reply to
    • Jan Schaumann

    @jschauma And this also prevents all sandboxing without suid helpers.

    In conversation about 3 months ago from hachyderm.io permalink
    • Embed this notice
      Jan Schaumann (jschauma@mstdn.social)'s status on Friday, 08-May-2026 09:22:35 JST Jan Schaumann Jan Schaumann

      The rxrpc module is likely easier for you to block, but if you can't blocklist the ESP kernel modules, note that that exploit path requires the ability to call `unshare(CLONE_NEWUSER | CLONE_NEWNET)`.

      That is

      ```
      sysctl -w kernel.unprivileged_userns_clone=1
      ```

      prevents the ESP exploit.

      (That also prevents that other silly variant.)

      #DirtyFrag

      In conversation about 3 months ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.