Linux containers in 500 lines of code
1
"Linux User Namespaces Might Not Be Secure Enough" by Erica Windisch:
If a (real) root user has had the SYS_CAP_ADMIN capability
removed, but then creates a user namespace, this capability is
restored for the (fake) root user. That is, before creating the
namespace, ‘mount’ would be denied, but following the creation of
the user namespace, the ‘mount’ syscall would magically work
again, albeit in a limited fashion. While limited in function,
it’s significant enough that given a (real) root use...
Read more at blog.lizzie.io