diff --git a/profiles/seccomp/default.json b/profiles/seccomp/default.json index 4a8418f6b5..52c65afa53 100644 --- a/profiles/seccomp/default.json +++ b/profiles/seccomp/default.json @@ -208,6 +208,7 @@ "lstat", "lstat64", "madvise", + "map_shadow_stack", "membarrier", "memfd_create", "memfd_secret", diff --git a/profiles/seccomp/default_linux.go b/profiles/seccomp/default_linux.go index 6369c79f0f..c0eec42d02 100644 --- a/profiles/seccomp/default_linux.go +++ b/profiles/seccomp/default_linux.go @@ -200,6 +200,7 @@ func DefaultProfile() *Seccomp { "lstat", "lstat64", "madvise", + "map_shadow_stack", // kernel v6.6, libseccomp v2.5.5 "membarrier", "memfd_create", "memfd_secret",