Hacker News new | ask | show | jobs
by jo909 3097 days ago
It is a reasonable _assumption_ that other container runtimes on linux might be affected by the same kernel bug. The article does not explore that and the author has no duty to do so just to avoid using a branded technology name.

How would you reasonably talk about "Linux containers" without having a very exhaustive list of all existing implementations and testing all of them? If one of them is not affected you are now factually wrong.

1 comments

The exploit overwrites kernel memory credentials of a task structure. That structure is the lynchpin of kernel security, including SELinux.