Skip to content

/dev should be mounted as "noexec" #35397

@n4ss

Description

@n4ss

/dev doesn't have the noexec mount option:

Options: []string{"nosuid", "strictatime", "mode=755", "size=65536k"},

Being a system tmpfs with RW rights, it'd be better to have no execution rights there.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area/runtimeRuntimearea/securitykind/enhancementEnhancements are not bugs or new features but can improve usability or performance.

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions