Skip to content

Commit

Permalink
Merge pull request #154 from bytedance/add-bpf-built-in-rule
Browse files Browse the repository at this point in the history
docs: Add a reference for `disallow-load-all-bpf-prog`
  • Loading branch information
Danny-Wei authored Dec 27, 2024
2 parents 2f0932f + ab0361d commit 51a4f3e
Show file tree
Hide file tree
Showing 4 changed files with 4 additions and 0 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -408,6 +408,7 @@ Refer to the following links for further information.
* [Taking the Elevator down to ring 0](https://blog.lumen.com/taking-the-elevator-down-to-ring-0)
* [CVE-2022-23222](https://www.openwall.com/lists/oss-security/2022/01/18/2)
* [CVE-2021-31440](https://www.zerodayinitiative.com/blog/2021/5/26/cve-2021-31440-an-incorrect-bounds-calculation-in-the-linux-kernel-ebpf-verifier)
* [CVE-2021-3490](https://www.crowdstrike.com/en-us/blog/exploiting-cve-2021-3490-for-container-escapes/)
* [CVE-2020-8835](https://www.zerodayinitiative.com/blog/2020/4/8/cve-2020-8835-linux-kernel-privilege-escalation-via-improper-ebpf-program-verification).
:::

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -403,6 +403,7 @@ User Namespace 可以被用于增强容器隔离性。但它的出现同时也
* [Taking the Elevator down to ring 0](https://blog.lumen.com/taking-the-elevator-down-to-ring-0)
* [CVE-2022-23222](https://www.openwall.com/lists/oss-security/2022/01/18/2)
* [CVE-2021-31440](https://www.zerodayinitiative.com/blog/2021/5/26/cve-2021-31440-an-incorrect-bounds-calculation-in-the-linux-kernel-ebpf-verifier)
* [CVE-2021-3490](https://www.crowdstrike.com/en-us/blog/exploiting-cve-2021-3490-for-container-escapes/)
* [CVE-2020-8835](https://www.zerodayinitiative.com/blog/2020/4/8/cve-2020-8835-linux-kernel-privilege-escalation-via-improper-ebpf-program-verification)
:::

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -403,6 +403,7 @@ User Namespace 可以被用于增强容器隔离性。但它的出现同时也
* [Taking the Elevator down to ring 0](https://blog.lumen.com/taking-the-elevator-down-to-ring-0)
* [CVE-2022-23222](https://www.openwall.com/lists/oss-security/2022/01/18/2)
* [CVE-2021-31440](https://www.zerodayinitiative.com/blog/2021/5/26/cve-2021-31440-an-incorrect-bounds-calculation-in-the-linux-kernel-ebpf-verifier)
* [CVE-2021-3490](https://www.crowdstrike.com/en-us/blog/exploiting-cve-2021-3490-for-container-escapes/)
* [CVE-2020-8835](https://www.zerodayinitiative.com/blog/2020/4/8/cve-2020-8835-linux-kernel-privilege-escalation-via-improper-ebpf-program-verification)
:::

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -408,6 +408,7 @@ Refer to the following links for further information.
* [Taking the Elevator down to ring 0](https://blog.lumen.com/taking-the-elevator-down-to-ring-0)
* [CVE-2022-23222](https://www.openwall.com/lists/oss-security/2022/01/18/2)
* [CVE-2021-31440](https://www.zerodayinitiative.com/blog/2021/5/26/cve-2021-31440-an-incorrect-bounds-calculation-in-the-linux-kernel-ebpf-verifier)
* [CVE-2021-3490](https://www.crowdstrike.com/en-us/blog/exploiting-cve-2021-3490-for-container-escapes/)
* [CVE-2020-8835](https://www.zerodayinitiative.com/blog/2020/4/8/cve-2020-8835-linux-kernel-privilege-escalation-via-improper-ebpf-program-verification).
:::

Expand Down

0 comments on commit 51a4f3e

Please sign in to comment.