summaryrefslogtreecommitdiff
path: root/cni
diff options
context:
space:
mode:
authorGiuseppe Scrivano <gscrivan@redhat.com>2022-02-28 09:48:52 +0100
committerGiuseppe Scrivano <gscrivan@redhat.com>2022-03-23 09:05:18 +0100
commitaafa80918a245edcbdaceb1191d749570f1872d0 (patch)
treebbd84ae1ea3eef9e6f9ffd4684956f4b0f8a0010 /cni
parentc39dffe83db9fa3cfa6897b971956821f1bbcce2 (diff)
downloadpodman-aafa80918a245edcbdaceb1191d749570f1872d0.tar.gz
podman-aafa80918a245edcbdaceb1191d749570f1872d0.tar.bz2
podman-aafa80918a245edcbdaceb1191d749570f1872d0.zip
do not set the inheritable capabilities
The kernel never sets the inheritable capabilities for a process, they are only set by userspace. Emulate the same behavior. Closes: CVE-2022-27649 Signed-off-by: Giuseppe Scrivano <gscrivan@redhat.com>
Diffstat (limited to 'cni')
0 files changed, 0 insertions, 0 deletions