On Thu, 2013-06-20 at 13:49 +0200, Alessandro Ghedini wrote: > Package: src:linux > Version: 3.9.6-1 > Severity: wishlist > > Hi, > > would it be possible to enable the CONFIG_USER_NS option? AFAICT as of v3.10 all > the parts that needed converting have been converted. Is this correct? Are there > any other related concerns? This is not correct; XFS has not been converted. And there are likely many more privilege escalation bugs related to users creating their own user-namespaces that haven't yet been discovered. I am reluctant to enable it again at this stage without limiting its use to root by default. Ben. -- Ben Hutchings Lowery's Law: If it jams, force it. If it breaks, it needed replacing anyway.
Attachment:
signature.asc
Description: This is a digitally signed message part