Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
abuild: bwrap: use --new-session to mitigate TIOCSTI escape (CVE-2017…
…-5226) Bubblewrap has an under-documented option which helps to protect against abuse of TIOCSTI ioctls against the session PTY to escape the build sandbox, the --new-session option. Related: containers/bubblewrap#555 Related: containers/bubblewrap#142 Related: https://news.ycombinator.com/item?id=30825088 Signed-off-by: Ariadne Conill <[email protected]>
- Loading branch information