angler-fishThe Vulnerability History Project

seccomp: LockPersonality boolean (#6193)

      Add LockPersonality boolean to allow locking down personality(2)
system call so that the execution domain can't be changed.
This may be useful to improve security because odd emulations
may be poorly tested and source of vulnerabilities, while
system services shouldn't need any weird personalities.
    
commit 78e864e5b3cc11b72ae663f49f42f158cafbfedf
-12
-1
+1 -32
-1
+2 -4
-19
-1
-36
expand_less