this post was submitted on 30 Aug 2026
74 points (98.7% liked)

Linux

14972 readers
343 users here now

A community for everything relating to the GNU/Linux operating system (except the memes!)

Also, check out:

Original icon base courtesy of lewing@isc.tamu.edu and The GIMP

founded 3 years ago
MODERATORS
top 12 comments
sorted by: hot top controversial new old
[–] traxex@lemmy.dbzer0.com 77 points 2 weeks ago

If you use Omarchy, the most important takeaway is simple: update to 4.0.1.

Or just delete that racist shitware.

[–] NaibofTabr@infosec.pub 37 points 2 weeks ago (2 children)

Once more for the people in the back:

CONTAINERS ARE NOT A SECURITY BARRIER

If you are relying on the container system to isolate and protect the OS from containerized apps, you are wrong.

[–] ColonelThirtyTwo@pawb.social 21 points 2 weeks ago (1 children)

FWIW this isn't a container escape. It's just the distro shipping a shitty default that lets the users on the host access root.

[–] NaibofTabr@infosec.pub 2 points 2 weeks ago (2 children)

On affected Omarchy systems, this means that the default user and all processes launched in that user session have access to root.

Hmm, maybe I'm misunderstanding. Does "all processes launched in that user session" not include containerized apps?

[–] ColonelThirtyTwo@pawb.social 6 points 2 weeks ago

The issue isn't that the containers have permissions they weren't assigned. It's that the system configuration allows any (host) user to make a container with any permissions, without sudo.

[–] equivocal@piefed.social 6 points 2 weeks ago (1 children)

The issue is that the docker service runs as root and their defaults added the user to a group that allows them to control that service without sudo

So, the root filesystem can just be passed as a volume to a container and then do whatever you want from there.

[–] NaibofTabr@infosec.pub -1 points 2 weeks ago

OK, so if you can pass the host root filesystem to a container and then write files or execute code with root privileges on that filesystem, I would definitely consider that a container escape. You're executing arbitrary code on the host from within a container.

[–] mlg@lemmy.world 3 points 2 weeks ago

I ain't got enuff hardware for qubesos

Go go gadget rootless podman UID mapping and cgroups black magic!

[–] ShutUpWesley@piefed.zip 34 points 2 weeks ago

What? The "AI first" OS is buggy and insecure? Who could have guessed?

Omarchy: I'm a fascist, btw.

[–] blarth@thelemmy.club 12 points 2 weeks ago

Omarchy is a distro for chuds.

[–] k0k0_belgium@lemmychan.org 1 points 2 weeks ago

Literally who linux