diff --git a/profiles/seccomp/default.json b/profiles/seccomp/default.json index 40ec582af0..033fccf57f 100644 --- a/profiles/seccomp/default.json +++ b/profiles/seccomp/default.json @@ -205,6 +205,7 @@ "lstat", "lstat64", "madvise", + "map_shadow_stack", "membarrier", "memfd_create", "memfd_secret", diff --git a/profiles/seccomp/default_linux.go b/profiles/seccomp/default_linux.go index 6e94ab024b..da9dcde480 100644 --- a/profiles/seccomp/default_linux.go +++ b/profiles/seccomp/default_linux.go @@ -197,6 +197,7 @@ func DefaultProfile() *Seccomp { "lstat", "lstat64", "madvise", + "map_shadow_stack", // kernel v6.6, libseccomp v2.5.5 "membarrier", "memfd_create", "memfd_secret",