Comment on Fixing the Linux Kernel Vulnerability CVE-2022-0185

<- View Parent
cypherpunks@lemmy.ml ⁨2⁩ ⁨years⁩ ago

Does it fix anything for Linux users who don't use kubernetes? The vast majority of don't. The obvious way everyone should fix CVE-2022-0185 today is by upgrading their kernel. If your distro hasn't shipped an update with the fix yet, you should find a new distro.

I was hoping that this link would tell me about the process of writing the Linux kernel patch (which I of course upgraded to already) which fixed the bug.

Instead I found an advertisement for a kubernetes-related product. I have no idea if "AccuKnox" is any good, but I do know that at this point in time nobody should be "fixing" CVE-2022-0185 by installing it - the correct fix is to upgrade Linux.

Perhaps this product is a good idea for kubernetes users to mitigate the next unprivileged user namespace related vulnerability; I stopped reading when I realized it was all about kubernetes.

Another good mitigation for Linux users in general is to simply disable unprivileged user namespaces altogether :)

source
Sort:hotnewtop