Skip to content

Commit

Permalink
bwrap.xml: Mention CVE-2017-5226 with --new-session
Browse files Browse the repository at this point in the history
Signed-off-by: Sebastian Pipping <[email protected]>
  • Loading branch information
hartwork committed Mar 5, 2023
1 parent 8280501 commit 2077ec7
Showing 1 changed file with 3 additions and 1 deletion.
4 changes: 3 additions & 1 deletion bwrap.xml
Original file line number Diff line number Diff line change
Expand Up @@ -463,7 +463,9 @@
</para><para>
Note: In a general sandbox, if you don't use --new-session, it is
recommended to use seccomp to disallow the TIOCSTI ioctl, otherwise
the application can feed keyboard input to the terminal.
the application can feed keyboard input to the terminal
which can e.g. lead to out-of-sandbox command execution
(see CVE-2017-5226).
</para></listitem>
</varlistentry>
<varlistentry>
Expand Down

0 comments on commit 2077ec7

Please sign in to comment.