浏览代码

Merge pull request from GHSA-jq35-85cj-fj4p

[23.0 backport] deny /sys/devices/virtual/powercap
Sebastiaan van Stijn 1 年之前
父节点
当前提交
48ebe353e4
共有 2 个文件被更改,包括 2 次插入0 次删除
  1. 1 0
      oci/defaults.go
  2. 1 0
      profiles/apparmor/template.go

+ 1 - 0
oci/defaults.go

@@ -98,6 +98,7 @@ func DefaultLinuxSpec() specs.Spec {
 				"/proc/sched_debug",
 				"/proc/scsi",
 				"/sys/firmware",
+				"/sys/devices/virtual/powercap",
 			},
 			ReadonlyPaths: []string{
 				"/proc/bus",

+ 1 - 0
profiles/apparmor/template.go

@@ -49,6 +49,7 @@ profile {{.Name}} flags=(attach_disconnected,mediate_deleted) {
   deny /sys/fs/c[^g]*/** wklx,
   deny /sys/fs/cg[^r]*/** wklx,
   deny /sys/firmware/** rwklx,
+  deny /sys/devices/virtual/powercap/** rwklx,
   deny /sys/kernel/security/** rwklx,
 
 {{if ge .Version 208095}}