SECURITY: LXC can read server dmesg

jinjer

Renowned Member
Oct 4, 2010
204
7
83
I have recently upgraded a cluster from 3.4 to 4.1

There's a security issue with LXC that I would like to bring to your attention.

Running dmesg inside a CT will show you the base server information. In some cases this reveals process info from other containers.

I would not expect this to be the case... perhaps a problem with my install ?

jinjer
 
Yes, it will probably be an issue.

On 4.2.8-1, when the OOM kicks in it dumps all processes of the server in the dmesg.

If, after this, one runs dmesg in the LXC, he gets to see everything and more from the running server.
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!