Skip to content

Add capabilities.drop=ALL to all container security contexts#1122

Merged
olevski merged 1 commit into
mainfrom
session_drop_all_cap
May 15, 2026
Merged

Add capabilities.drop=ALL to all container security contexts#1122
olevski merged 1 commit into
mainfrom
session_drop_all_cap

Conversation

@aledegano

@aledegano aledegano commented May 12, 2026

Copy link
Copy Markdown
Contributor

In my testing I have found out that this is also sufficient to block exploits like Copy-Fail(CVE-2026-31431) and Dirty-Frag(CVE-2026-43284, CVE-2026-43500).

Additionally it is probably a good idea to drop all capabilities from Renku user-sessions to limit the surface of attack.

/deploy

@RenkuBot

Copy link
Copy Markdown
Contributor

You can access the deployment of this PR at https://renku-ci-am-1122.dev.renku.ch

@aledegano aledegano marked this pull request as ready for review May 12, 2026 13:50
@aledegano aledegano requested review from a team and olevski as code owners May 12, 2026 13:50
@olevski olevski merged commit b9823e1 into main May 15, 2026
16 of 23 checks passed
@olevski olevski deleted the session_drop_all_cap branch May 15, 2026 07:40
@RenkuBot

Copy link
Copy Markdown
Contributor

Tearing down the temporary RenkuLab deplyoment for this PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants