summaryrefslogtreecommitdiffstats
path: root/drivers/mfd
diff options
context:
space:
mode:
authorJohn Johansen <john.johansen@canonical.com>2022-09-10 01:00:09 +0200
committerJohn Johansen <john.johansen@canonical.com>2023-10-19 00:49:02 +0200
commitfa9b63adabcfa9b724120ef3352cf6fb82b4b9a5 (patch)
treedc093ea12c7ae548e981bc1f675d7f974a6366f0 /drivers/mfd
parentapparmor: allow restricting unprivileged change_profile (diff)
downloadlinux-fa9b63adabcfa9b724120ef3352cf6fb82b4b9a5.tar.xz
linux-fa9b63adabcfa9b724120ef3352cf6fb82b4b9a5.zip
apparmor: add user namespace creation mediation
Unprivileged user namespace creation is often used as a first step in privilege escalation attacks. Instead of disabling it at the sysrq level, which blocks its legitimate use as for setting up a sandbox, allow control on a per domain basis. This allows an admin to quickly lock down a system while also still allowing legitimate use. Reviewed-by: Georgia Garcia <georgia.garcia@canonical.com> Signed-off-by: John Johansen <john.johansen@canonical.com>
Diffstat (limited to 'drivers/mfd')
0 files changed, 0 insertions, 0 deletions