Hacker News new | ask | show | jobs
by tryauuum 22 days ago
Not all device files, only /dev/kvm. I assume the logic was "with /dev/kvm access the user can ...allocate memory and execute code, which they already can, so why not allow it?". Could also make rootless isolation easier
1 comments

Different kernel modules might have different vulnerabilities.