Hacker News new | ask | show | jobs
by stratos123 45 days ago
It's equivalent to setting no_new_privs on the container process, so it'd mean you have to grant a privelege to the container process if you want any children to have access to it. It sure sounds funny in a CVE context, though.