Commit be5610c
committed
BACKPORT: Add /proc/scsi to masked paths
This is writeable, and can be used to remove devices. Containers do
not need to know about scsi devices.
Fix https://nvd.nist.gov/vuln/detail/CVE-2017-16539
Signed-off-by: Antonio Murdaca <runcom@redhat.com>1 parent 6f56618 commit be5610c
1 file changed
Lines changed: 1 addition & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
84 | 84 | | |
85 | 85 | | |
86 | 86 | | |
| 87 | + | |
87 | 88 | | |
88 | 89 | | |
89 | 90 | | |
| |||
0 commit comments