Get the latest tech news

OSS-SEC: Three bypasses of Ubuntu's unprivileged user namespace restrictions


From: Qualys Security Advisory <qsa () qualys com> Date: Thu, 27 Mar 2025 17:44:15 +0000 Qualys Security Advisory Three bypasses of Ubuntu's unprivileged user namespace restrictions ======================================================================== Contents ======================================================================== Summary Bypass via aa-exec Bypass via busybox Bypass via LD_PRELOAD Acknowledgments Timeline (advisory sent to the Ubuntu Security Team on January 15, 2025) ------------------------------------------------------------------------ Prologue, from https://grsecurity.net/10_years_of_linux_security.pdf: + February 2013 (v3.8) - Unprivileged User Namespace support added - Greatly increased kernel attack surface, exposed many interfaces that previously saw little security scrutiny + Attack surface exposed by unprivileged user namespaces isn't decreasing anytime soon - Even more functionality being exposed ------------------------------------------------------------------------ ======================================================================== Summary ======================================================================== Ubuntu 23.10 introduced unprivileged user namespace restrictions (the sysctl kernel.apparmor_restrict_unprivileged_userns) and Ubuntu 24.04 enabled them by default. From Alex Murray's excellent blog post at https://ubuntu.com/blog/whats-new-in-security-for-ubuntu-24-04-lts: "Unprivileged user namespaces are a widely used feature of the Linux kernel, providing additional security isolation for applications, and are often employed as part of a sandbox environment.

From: Qualys Security Advisory <qsa () qualys com> Date: Thu, 27 Mar 2025 17:44:15 +0000 By Date Three bypasses of Ubuntu's unprivileged user namespace restrictions Qualys Security Advisory (Mar 27)

Get the Android app

Or read this on Hacker News

Read more on:

Photo of bypasses

bypasses

Photo of ubuntu

ubuntu

Photo of OSS-SEC

OSS-SEC

Related news:

News photo

GNOME 48 & KDE Plasma 6.3 Delivering Great Wayland Desktop Experience On Ubuntu 25.04 For Linux Gaming

News photo

Ubuntu Provides More Insight Into Their Decision Not To "-O3" Optimize All Packages

News photo

Ubuntu 25.04 Beta Officially Released