A missing check allows unprivileged attackers to escape containers and execute arbitrary commands in the kernel. To go along with the “Dirty Pipe” Linux security bug coming to light, two researchers ...
Processes running on the GPU are reluctant to be aborted. After all, the computing-intensive tasks should not have to be restarted. The new kernel declares war on forced ejection via cgroups. Linux ...