Guest session processes are not confined in 16.10 and newer releases
Bug #1663157 reported by
Tyler Hicks
This bug affects 15 people
| Affects | Status | Importance | Assigned to | Milestone | |
|---|---|---|---|---|---|
| Light Display Manager |
New
|
Undecided
|
Unassigned | ||
| lightdm (Ubuntu) |
Fix Released
|
High
|
Balint Reczey | ||
| Yakkety |
Fix Released
|
High
|
Tyler Hicks | ||
| Zesty |
Fix Released
|
High
|
Tyler Hicks | ||
| Artful |
Fix Released
|
High
|
Balint Reczey | ||
Bug Description
Processes launched under a lightdm guest session are not confined by the /usr/lib/
The simple test case is to log into a guest session, launch a terminal with ctrl-alt-t, and run the following command:
$ cat /proc/self/
Expected output, as seen in Ubuntu 16.04 LTS, is:
/usr/lib/
Running the command inside of an Ubuntu 16.10 and newer guest session results in:
unconfined
CVE References
| Changed in apparmor (Ubuntu): | |
| importance: | Undecided → High |
| Changed in lightdm (Ubuntu Zesty): | |
| importance: | Undecided → High |
| Changed in lightdm (Ubuntu Yakkety): | |
| importance: | Undecided → High |
| Changed in lightdm (Ubuntu Artful): | |
| status: | New → Triaged |
| Changed in lightdm (Ubuntu Zesty): | |
| status: | New → Triaged |
| Changed in lightdm (Ubuntu Yakkety): | |
| status: | New → Triaged |
| tags: | added: patch |
| Changed in lightdm (Ubuntu Artful): | |
| assignee: | nobody → Robert Ancell (robert-ancell) |
| Changed in lightdm: | |
| assignee: | nobody → Robert Ancell (robert-ancell) |
| Changed in lightdm (Ubuntu Yakkety): | |
| assignee: | nobody → Tyler Hicks (tyhicks) |
| Changed in lightdm (Ubuntu Zesty): | |
| assignee: | nobody → Tyler Hicks (tyhicks) |
| Changed in lightdm (Ubuntu Artful): | |
| status: | Triaged → In Progress |
| no longer affects: | apparmor (Ubuntu) |
| tags: | added: id-5a57962350afc7d4aa391919 |
| Changed in lightdm: | |
| assignee: | Robert Ancell (robert-ancell) → nobody |
To post a comment you must log in.

After coming back to this bug, I noticed that Robert was not subscribed and couldn't see the bug. He's now subscribed.