OpenVZ Forum


Home » Mailing lists » Users » Security risks in ve_allow_kthreads
Re: Security risks in ve_allow_kthreads [message #25791 is a reply to message #25776] Wed, 09 January 2008 07:52 Go to previous message
dev is currently offline  dev
Messages: 1693
Registered: September 2005
Location: Moscow
Senior Member

Jakob Goldbach wrote:
> Hi,
> 
> What securiy risks do I impose on myself when enabling kernel threads
> inside the VE ?

1. if kernel thread doesn't terminate on VE stop - VE stop will be blocked.
2. security implications can be that kernel threads usually can do things
   which user space applications can't. So security implications depend
   on what thread in question does.
3. if your system is quite trusted (2) is not an issue at all.
   only (1) must be concerned.

Kirill
 
Read Message
Read Message
Read Message
Read Message
Previous Topic: Hello, Some Problems With Open VZ
Next Topic: post-start and stop scripts
Goto Forum:
  


Current Time: Sat May 10 09:38:34 GMT 2025

Total time taken to generate the page: 0.03798 seconds