| ▲ | bloppe 8 hours ago | |||||||
CVEs for runc are much more frequent than CVEs for KVM. The attack surface area is bigger, and containers were never intended as a security boundary, but rather as a resource management tool. | ||||||||
| ▲ | dathinab 4 hours ago | parent | next [-] | |||||||
through just from scanning the feature side > Your files and your account [..] > Ports and windows on the host it is quite likely that you can break out even with no linux containers related CVEs. --isolate does seem to fix that somehow but is explicit opt. in and "more painful to use" ... (which creates a UX challenge unlikely to end well from a security POV). | ||||||||
| ▲ | akdev1l 3 hours ago | parent | prev [-] | |||||||
libkrun exists so we can just run containers inside a virtualized environment without special tooling | ||||||||
| ||||||||