I'm going to take a look at both arguments and decide for myself. No need to name drop.
I'm going to take a look at both arguments and decide for myself. No need to name drop.
Give it a rest. This is a semi-anonymous forum where people's identities aren't tied to their usernames. This isn't name dropping, it's providing helpful context.
Some of the comments from Red Hat previously implied that they thought the vulnerability could only be exploited via ptrace, which SELinux denied by default for Docker containers. That's definitely not true; ptrace was used in the PoC because it's easy and likely to win the race condition, but you can also grab file descriptors out of /proc/$pid/fd.
However, the blog post appears to show SELinux stopping attacks that don't involve ptrace, because SELinux forbids writing to an open file or an open network socket that has the wrong context. If Docker believes there are attack vectors that aren't covered by the default SELinux policies (such as writing to something that's not a regular file or network socket), they might be unwilling to disclose that too loudly until Red Hat gets around to saying "Uh, actually please patch".
Edit: Don't downvote people trying to help me improve my english. :(
Just kidding.
It's relevant and vital to know the background of people who are making statements like this.
And sorry but not everyone is a kernel engineer who can navigate the truth between RedHat and Docker.