Hacker News new | ask | show | jobs
by insanitybit 19 days ago
There are a million ways to load a kernel module from inside of a container into the host kernel (ie: to trigger a load), but seccomp/ linux caps will block the direct ways (as another commenter notes).