NEW: Unlock the Future of Finance with CRYPTO ENDEVR - Explore, Invest, and Prosper in Crypto!
Crypto Endevr
  • Top Stories
    • Latest News
    • Trending
    • Editor’s Picks
  • Media
    • YouTube Videos
      • Interviews
      • Tutorials
      • Market Analysis
    • Podcasts
      • Latest Episodes
      • Featured Podcasts
      • Guest Speakers
  • Insights
    • Tokens Talk
      • Community Discussions
      • Guest Posts
      • Opinion Pieces
    • Artificial Intelligence
      • AI in Blockchain
      • AI Security
      • AI Trading Bots
  • Learn
    • Projects
      • Ethereum
      • Solana
      • SUI
      • Memecoins
    • Educational
      • Beginner Guides
      • Advanced Strategies
      • Glossary Terms
No Result
View All Result
Crypto Endevr
  • Top Stories
    • Latest News
    • Trending
    • Editor’s Picks
  • Media
    • YouTube Videos
      • Interviews
      • Tutorials
      • Market Analysis
    • Podcasts
      • Latest Episodes
      • Featured Podcasts
      • Guest Speakers
  • Insights
    • Tokens Talk
      • Community Discussions
      • Guest Posts
      • Opinion Pieces
    • Artificial Intelligence
      • AI in Blockchain
      • AI Security
      • AI Trading Bots
  • Learn
    • Projects
      • Ethereum
      • Solana
      • SUI
      • Memecoins
    • Educational
      • Beginner Guides
      • Advanced Strategies
      • Glossary Terms
No Result
View All Result
Crypto Endevr
No Result
View All Result

Ubuntu namespace vulnerability should be addressed quickly: Expert

Ubuntu namespace vulnerability should be addressed quickly: Expert
Share on FacebookShare on Twitter

Features Supposed to Improve Security

Organizations using centralized configuration tools like Ansible may deploy changes with regularly scheduled maintenance or reboot windows. However, this approach may not have a significant impact on security. As Beggs stated, "there is little impact of not ‘patching’ the vulnerability."

Unintended Consequences

Ironically, last October, Ubuntu introduced AppArmor-based features to improve security by reducing the attack surface from unprivileged user namespaces in the Linux kernel. Unfortunately, this feature did not quite live up to its promise. As Beggs pointed out, "This is an unintended consequence where a security control was put in place but it isn’t fully applied, so it allows anyone to push and escalate their privileges."

Three Bypasses

Unprivileged user namespaces are a feature in the Linux kernel that are supposed to provide additional sandboxing functionality for programs such as container runtimes. This feature enables unprivileged users to gain administrator (root) permissions within a confined environment, without giving them elevated permissions on the host system. However, unprivileged user namespaces have been repeatedly used to exploit kernel vulnerabilities.

Security Hardening Measure

To address this issue, the AppArmor restriction was added to Ubuntu 23.10 and 24.04 LTS as a security hardening measure. This restriction was designed to act as a security control, preventing users from exploiting kernel vulnerabilities. However, Qualys discovered three different bypasses, each of which allows a local attacker to create user namespaces with full administrator capabilities.

Bypass 1: Escaping the Sandbox

The first bypass involves creating a new user namespace and then escaping the sandbox by using the unshare system call. This allows the attacker to gain elevated privileges and exploit kernel vulnerabilities.

Bypass 2: Spoofing the Sandbox

The second bypass involves spoofing the sandbox by creating a new user namespace and then modifying the nsproxy struct to point to the original namespace. This allows the attacker to bypass the security restrictions and gain elevated privileges.

Bypass 3: Using the setns System Call

The third bypass involves using the setns system call to switch to a new user namespace. This allows the attacker to bypass the security restrictions and gain elevated privileges.

Conclusion

In conclusion, the AppArmor-based features introduced by Ubuntu to improve security have been found to have unintended consequences. The three bypasses discovered by Qualys demonstrate that the security hardening measure implemented by Ubuntu is not effective in preventing users from exploiting kernel vulnerabilities. As a result, organizations should reconsider their approach to security and implement more robust measures to protect against kernel vulnerabilities.

FAQs

Q: What are unprivileged user namespaces?
A: Unprivileged user namespaces are a feature in the Linux kernel that provide additional sandboxing functionality for programs such as container runtimes. They enable unprivileged users to gain administrator (root) permissions within a confined environment, without giving them elevated permissions on the host system.

Q: What is the purpose of the AppArmor restriction in Ubuntu 23.10 and 24.04 LTS?
A: The AppArmor restriction was added to Ubuntu 23.10 and 24.04 LTS as a security hardening measure to prevent users from exploiting kernel vulnerabilities. However, Qualys discovered three different bypasses that allow local attackers to create user namespaces with full administrator capabilities.

Q: How do the bypasses work?
A: The bypasses involve creating a new user namespace, escaping the sandbox, spoofing the sandbox, or using the setns system call to switch to a new user namespace. Each of these bypasses allows a local attacker to create user namespaces with full administrator capabilities, enabling them to exploit kernel vulnerabilities.

Q: What are the implications of these bypasses?
A: The implications are significant, as they demonstrate that the security hardening measure implemented by Ubuntu is not effective in preventing users from exploiting kernel vulnerabilities. Organizations should reconsider their approach to security and implement more robust measures to protect against kernel vulnerabilities.

cryptoendevr

cryptoendevr

Related Stories

“Ransomware, was ist das?”

“Ransomware, was ist das?”

July 10, 2025
0

Rewrite the width="5175" height="2910" sizes="(max-width: 5175px) 100vw, 5175px">Gefahr nicht erkannt, Gefahr nicht gebannt.Leremy – shutterstock.com KI-Anbieter Cohesity hat 1.000 Mitarbeitende...

BTR: AI, Compliance, and the Future of Mainframe Modernization

BTR: AI, Compliance, and the Future of Mainframe Modernization

July 10, 2025
0

Rewrite the As artificial intelligence (AI) reshapes the enterprise technology landscape, industry leaders are rethinking modernization strategies to balance agility,...

Warning to ServiceNow admins: Fix your access control lists now

Warning to ServiceNow admins: Fix your access control lists now

July 9, 2025
0

Rewrite the “This vulnerability was relatively simple to exploit, and required only minimal table access, such as a weak user...

Palantir and Tomorrow.io Partner to Operationalize Global Weather Intelligence and Agentic AI

Palantir and Tomorrow.io Partner to Operationalize Global Weather Intelligence and Agentic AI

July 9, 2025
0

Rewrite the Palantir Technologies Inc., a leading provider of enterprise operating systems, and Tomorrow.io, a leading weather intelligence and resilience...

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

Bitcoin Short-Term Holder Shakeout Could Accelerate Recovery Above Key Level

Bitcoin Short-Term Holder Shakeout Could Accelerate Recovery Above Key Level

December 3, 2025
ETH briefly touches K but traders remain skeptical: Here’s why

ETH briefly touches $3K but traders remain skeptical: Here’s why

December 3, 2025
Ether Treasury Stocks Lead Crypto Recovery Gains

Ether Treasury Stocks Lead Crypto Recovery Gains

December 3, 2025
Haven – Blockchain With Biometric Authentication

Haven – Blockchain With Biometric Authentication

December 3, 2025
Here’s How Many Shiba Inu (SHIB) Tokens Were Burned in November

Here’s How Many Shiba Inu (SHIB) Tokens Were Burned in November

December 2, 2025

Our Newsletter

Join TOKENS for a quick weekly digest of the best in crypto news, projects, posts, and videos for crypto knowledge and wisdom.

CRYPTO ENDEVR

About Us

Crypto Endevr aims to simplify the vast world of cryptocurrencies and blockchain technology for our readers by curating the most relevant and insightful articles from around the web. Whether you’re a seasoned investor or new to the crypto scene, our mission is to deliver a streamlined feed of news and analysis that keeps you informed and ahead of the curve.

Links

Home
Privacy Policy
Terms and Services

Resources

Glossary

Other

About Us
Contact Us

Our Newsletter

Join TOKENS for a quick weekly digest of the best in crypto news, projects, posts, and videos for crypto knowledge and wisdom.

© Copyright 2024. All Right Reserved By Crypto Endevr.

No Result
View All Result
  • Top Stories
    • Latest News
    • Trending
    • Editor’s Picks
  • Media
    • YouTube Videos
      • Interviews
      • Tutorials
      • Market Analysis
    • Podcasts
      • Latest Episodes
      • Featured Podcasts
      • Guest Speakers
  • Insights
    • Tokens Talk
      • Community Discussions
      • Guest Posts
      • Opinion Pieces
    • Artificial Intelligence
      • AI in Blockchain
      • AI Security
      • AI Trading Bots
  • Learn
    • Projects
      • Ethereum
      • Solana
      • SUI
      • Memecoins
    • Educational
      • Beginner Guides
      • Advanced Strategies
      • Glossary Terms

Copyright © 2024. All Right Reserved By Crypto Endevr