why do you need to run inside a namespace? haven't tried it yet but can't you create dccp sockets as a non-privileged user? @andreyknvl
-
-
-
You can, so namespace support is not technically required to exploit the bug, but it made things easier for two reasons:
@vnik5287 -
1: need CAP_SYS_NICE to sched_setaffinity (percpu freelists) and 2: need CAT_NET_RAW to create AF_PACKET sockets (SM*P bypass)
@vnik5287 -
Though looking at the code now it seems you only need CAP_SYS_NICE to set affinity of another process
@vnik5287 http://lxr.free-electrons.com/source/kernel/sched/core.c#L4686 … -
yeah, you don't need it for setting affinity on the "current" process. But still need it for the second case
End of conversation
New conversation -
-
-
How widespread is support for DCCP in real world distros? Android kernels (for example) are usually compiled without it
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
-
-
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.