aboutsummaryrefslogtreecommitdiffstats
path: root/RELNOTES
diff options
context:
space:
mode:
authorLibravatar rusty-snake <41237666+rusty-snake@users.noreply.github.com>2020-10-16 18:51:37 +0200
committerLibravatar rusty-snake <41237666+rusty-snake@users.noreply.github.com>2020-10-23 11:01:12 +0200
commit1ebdf894c675925109031b3fbb859478a2ece566 (patch)
tree6e656ad5d5e4047bcdc078aefbf926e084309589 /RELNOTES
parent0.9.64 testing (diff)
downloadfirejail-1ebdf894c675925109031b3fbb859478a2ece566.tar.gz
firejail-1ebdf894c675925109031b3fbb859478a2ece566.tar.zst
firejail-1ebdf894c675925109031b3fbb859478a2ece566.zip
Allow --tmpfs inside $HOME for unprivileged users
--tmpfs was added in 0.9.14 and restricted to root only in 0.9.38 due to priv-esc CVE-2016-10117 (e.g. --tmpfs=/etc and modify /etc/sudoers). This commit reintroduce it for normal users, if the realpath of it is inside users-home.
Diffstat (limited to 'RELNOTES')
-rw-r--r--RELNOTES3
1 files changed, 3 insertions, 0 deletions
diff --git a/RELNOTES b/RELNOTES
index f38b42c4b..d9036898f 100644
--- a/RELNOTES
+++ b/RELNOTES
@@ -1,3 +1,6 @@
1firejail (0.9.65) baseline; urgency=low
2 * allow --tmpfs inside $HOME for unprivileged users
3
1firejail (0.9.64) baseline; urgency=low 4firejail (0.9.64) baseline; urgency=low
2 * replaced --nowrap option with --wrap in firemon 5 * replaced --nowrap option with --wrap in firemon
3 * The blocking action of seccomp filters has been changed from 6 * The blocking action of seccomp filters has been changed from