3/29/2025 at 9:54:46 PM
Important caveat: this is not itself a vulnerability; you still need a kernel `CAP_SYS_ADMIN` vulnerability if you want to actually do something evil.(I also expect that if you're already in a restricted AA profile it's not easy to switch to a less-restrictive one, but I think a lot of security tools are bad at thinking about multi-process interpreters)
by o11c