Friday, 20 Mar 2026
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Global Market > Ubuntu namespace vulnerability should be addressed quickly: Expert
Global Market

Ubuntu namespace vulnerability should be addressed quickly: Expert

Last updated: March 29, 2025 4:10 pm
Published March 29, 2025
Share
Linux source code with a binary background. 3D rendered Illustration.
SHARE

Contents
Options supposed to enhance safetyThree bypasses

Thus, “there may be little influence of not ‘patching’ the vulnerability,” he mentioned. “Organizations utilizing centralized configuration instruments like Ansible could deploy these adjustments with repeatedly scheduled upkeep or reboot home windows.” 

Options supposed to enhance safety

Satirically, final October Ubuntu launched AppArmor-based options to enhance safety by lowering the assault floor from unprivileged person namespaces within the Linux kernel. It didn’t fairly do this.

“That is an unintended consequence the place a safety management was put in place nevertheless it isn’t absolutely utilized,” mentioned Beggs, “so it permits anybody to push and escalate their privileges.”

Three bypasses

Unprivileged person namespaces are a characteristic within the Linux kernel which might be supposed to supply extra sandboxing performance for applications similar to container runtimes, says Ubuntu. It permits unprivileged customers to realize administrator (root) permissions inside a confined atmosphere, with out giving them elevated permissions on the host system.

Nonetheless, unprivileged person namespaces have been repeatedly used to use kernel vulnerabilities, so the AppArmor restriction added to Ubuntu 23.10 and 24.04 LTS was presupposed to act as a safety hardening measure.

However Qualys discovered three different bypasses, every of which permits an area attacker to create person namespaces with full administrator capabilities, and subsequently to nonetheless exploit vulnerabilities in kernel elements that require capabilities similar to CAP_SYS_ADMIN or CAP_NET_ADMIN:

Source link

See also  Update your Windows PC to avoid a serious Wi-Fi vulnerability
TAGGED: addressed, expert, namespace, Quickly, Ubuntu, vulnerability
Share This Article
Twitter Email Copy Link Print
Previous Article Layer Health Layer Health Raises $21M in Series A Funding
Next Article PU Prime Becomes the Official Regional Sponsor of the Argentina National Football Team PU Prime Becomes the Official Regional Sponsor of the Argentina National Football Team
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

Calling all gen AI disruptors of the enterprise! Apply now to present at Transform 2025

Be a part of our day by day and weekly newsletters for the most recent…

December 6, 2024

AI-enhanced Cooling System Optimizer reduces energy consumption by up to 40%

The patent-pending AI know-how makes use of a hybrid deep studying mannequin, leveraging machine studying,…

April 27, 2025

URBN tests agentic AI to automate retail reporting

Retail choices typically depend upon weekly efficiency experiences, however compiling these experiences can take hours…

February 17, 2026

Bigger isn’t always better: Examining the business case for multi-million token LLMs

Be part of our each day and weekly newsletters for the newest updates and unique…

April 13, 2025

Itaú Invests in Kanastra’s Series A Extension

Kanastra, a Uberlândia, Minas Gerais, Brazil-based expertise and fiduciary companies firm for funds and securitizations,…

February 4, 2025

You Might Also Like

Antin Infrastructure Partners completes takeover of NorthC
Global Market

Antin Infrastructure Partners completes takeover of NorthC

By saad
Cloud Computing Disaster Recovery Solutions Concept - Cloud DR - Services Companies Use for the Purpose of Backing Up Resources into a Cloud Environment - 3D Illustration
Global Market

Nile adds microsegmentation and native NAC to its secure NaaS platform

By saad
Planning delays continue to delay Tritax's Slough data centre
Global Market

Planning delays continue to delay Tritax’s Slough data centre

By saad
A photograph of a row of Ethernet cables plugged into ports, with a warning sign illuminated above one of the ports.
Global Market

Telnet vulnerability opens door to remote code execution as root

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.