Removed references to clearlinux.org

This commit is contained in:
David Klimesh
2023-08-02 18:43:34 -07:00
committed by djklimes
parent f509dbc681
commit 9f8ef77581
4685 changed files with 273986 additions and 273986 deletions
+74 -74
View File
@@ -8,7 +8,7 @@
* html--node.html.twig
x html.html.twig
-->
<!-- BEGIN OUTPUT from 'modules/custom/clearlinux_org/themes/clearlinux_theme/templates/layout/html.html.twig' -->
<!-- BEGIN OUTPUT from 'modules/custom/clearlinux.github.io/themes/clearlinux_theme/templates/layout/html.html.twig' -->
<!DOCTYPE html>
<html lang="en" dir="ltr" prefix="content: http://purl.org/rss/1.0/modules/content/ dc: http://purl.org/dc/terms/ foaf: http://xmlns.com/foaf/0.1/ og: http://ogp.me/ns# rdfs: http://www.w3.org/2000/01/rdf-schema# schema: http://schema.org/ sioc: http://rdfs.org/sioc/ns# sioct: http://rdfs.org/sioc/types# skos: http://www.w3.org/2004/02/skos/core# xsd: http://www.w3.org/2001/XMLSchema# ">
<head>
@@ -18,7 +18,7 @@
<meta name="description" content="By Eric Adams and John Andersen, Intel Corporation. Overview The Dirty COW exploit (CVE-2016-5195) is a race condition that allows an attacker to gain root access to any vulnerable system, and can even be exploited from within a Docker* container. This vulnerability existed in the Linux* kernel for nine years before it was discovered." />
<meta property="og:site_name" content="Clear Linux* Project" />
<meta property="og:type" content="Blog" />
<meta property="og:url" content="https://clearlinux.org/news-blogs/how-intel-clear-containers-protects-against-root-kernel-exploits-dirty-cow" />
<meta property="og:url" content="https://clearlinux.github.io/news-blogs/how-intel-clear-containers-protects-against-root-kernel-exploits-dirty-cow" />
<meta property="og:title" content="How Intel® Clear Containers protects against root kernel exploits like Dirty COW" />
<meta property="og:description" content="By Eric Adams and John Andersen, Intel Corporation. Overview The Dirty COW exploit (CVE-2016-5195) is a race condition that allows an attacker to gain root access to any vulnerable system, and can even be exploited from within a Docker* container. This vulnerability existed in the Linux* kernel for nine years before it was discovered." />
<meta name="Generator" content="Drupal 9 (https://www.drupal.org)" />
@@ -26,44 +26,44 @@
<meta name="HandheldFriendly" content="true" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
<style>div#sliding-popup, div#sliding-popup .eu-cookie-withdraw-banner, .eu-cookie-withdraw-tab {background: #0779BF} div#sliding-popup.eu-cookie-withdraw-wrapper { background: transparent; } #sliding-popup h1, #sliding-popup h2, #sliding-popup h3, #sliding-popup p, #sliding-popup label, #sliding-popup div, .eu-cookie-compliance-more-button, .eu-cookie-compliance-secondary-button, .eu-cookie-withdraw-tab { color: #ffffff;} .eu-cookie-withdraw-tab { border-color: #ffffff;}</style>
<link rel="icon" href="https://clearlinux.org/modules/custom/clearlinux_org/themes/clearlinux_theme/favicon.ico" type="image/vnd.microsoft.icon" />
<link rel="icon" href="https://clearlinux.github.io/modules/custom/clearlinux.github.io/themes/clearlinux_theme/favicon.ico" type="image/vnd.microsoft.icon" />
<link rel="canonical" href="663.html" />
<link rel="shortlink" href="663.html" />
<script src="https://clearlinux.org/sites/default/files/eu_cookie_compliance/eu_cookie_compliance.script.js?rl3r25" defer></script>
<script src="https://clearlinux.github.io/sites/default/files/eu_cookie_compliance/eu_cookie_compliance.script.js?rl3r25" defer></script>
<title>How Intel® Clear Containers protects against root kernel exploits like Dirty COW | Clear Linux* Project</title>
<link rel="stylesheet" media="all" href="https://clearlinux.org/core/themes/stable/css/system/components/ajax-progress.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.org/core/themes/stable/css/system/components/align.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.org/core/themes/stable/css/system/components/autocomplete-loading.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.org/core/themes/stable/css/system/components/fieldgroup.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.org/core/themes/stable/css/system/components/container-inline.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.org/core/themes/stable/css/system/components/clearfix.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.org/core/themes/stable/css/system/components/details.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.org/core/themes/stable/css/system/components/hidden.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.org/core/themes/stable/css/system/components/item-list.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.org/core/themes/stable/css/system/components/js.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.org/core/themes/stable/css/system/components/nowrap.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.org/core/themes/stable/css/system/components/position-container.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.org/core/themes/stable/css/system/components/progress.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.org/core/themes/stable/css/system/components/reset-appearance.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.org/core/themes/stable/css/system/components/resize.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.org/core/themes/stable/css/system/components/sticky-header.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.org/core/themes/stable/css/system/components/system-status-counter.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.org/core/themes/stable/css/system/components/system-status-report-counters.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.org/core/themes/stable/css/system/components/system-status-report-general-info.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.org/core/themes/stable/css/system/components/tabledrag.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.org/core/themes/stable/css/system/components/tablesort.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.org/core/themes/stable/css/system/components/tree-child.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.org/modules/contrib/eu_cookie_compliance/css/eu_cookie_compliance.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.org/modules/contrib/extlink/extlink.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.github.io/core/themes/stable/css/system/components/ajax-progress.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.github.io/core/themes/stable/css/system/components/align.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.github.io/core/themes/stable/css/system/components/autocomplete-loading.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.github.io/core/themes/stable/css/system/components/fieldgroup.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.github.io/core/themes/stable/css/system/components/container-inline.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.github.io/core/themes/stable/css/system/components/clearfix.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.github.io/core/themes/stable/css/system/components/details.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.github.io/core/themes/stable/css/system/components/hidden.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.github.io/core/themes/stable/css/system/components/item-list.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.github.io/core/themes/stable/css/system/components/js.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.github.io/core/themes/stable/css/system/components/nowrap.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.github.io/core/themes/stable/css/system/components/position-container.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.github.io/core/themes/stable/css/system/components/progress.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.github.io/core/themes/stable/css/system/components/reset-appearance.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.github.io/core/themes/stable/css/system/components/resize.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.github.io/core/themes/stable/css/system/components/sticky-header.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.github.io/core/themes/stable/css/system/components/system-status-counter.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.github.io/core/themes/stable/css/system/components/system-status-report-counters.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.github.io/core/themes/stable/css/system/components/system-status-report-general-info.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.github.io/core/themes/stable/css/system/components/tabledrag.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.github.io/core/themes/stable/css/system/components/tablesort.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.github.io/core/themes/stable/css/system/components/tree-child.module.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.github.io/modules/contrib/eu_cookie_compliance/css/eu_cookie_compliance.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.github.io/modules/contrib/extlink/extlink.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://use.fontawesome.com/releases/v6.1.0/css/all.css" />
<link rel="stylesheet" media="all" href="https://use.fontawesome.com/releases/v6.1.0/css/v4-shims.css" />
<link rel="stylesheet" media="all" href="https://clearlinux.org/libraries/codesnippet/lib/highlight/styles/monokai_sublime.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.org/modules/custom/clearlinux_org/themes/clearlinux_theme/css/styles.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.github.io/libraries/codesnippet/lib/highlight/styles/monokai_sublime.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://clearlinux.github.io/modules/custom/clearlinux.github.io/themes/clearlinux_theme/css/styles.css?rl3r25" />
<link rel="stylesheet" media="all" href="https://cdnjs.cloudflare.com/ajax/libs/OwlCarousel2/2.2.1/assets/owl.carousel.min.css" integrity="sha256-AWqwvQ3kg5aA5KcXpX25sYKowsX97sTCTbeo33Yfyk0=" crossorigin="anonymous" />
<script src="https://clearlinux.org/core/assets/vendor/modernizr/modernizr.min.js?v=3.11.7"></script>
<script src="https://clearlinux.org/core/misc/modernizr-additional-tests.js?v=3.11.7"></script>
<script src="https://clearlinux.github.io/core/assets/vendor/modernizr/modernizr.min.js?v=3.11.7"></script>
<script src="https://clearlinux.github.io/core/misc/modernizr-additional-tests.js?v=3.11.7"></script>
</head>
<body class="alias--news-blogs-how-intel-clear-containers-protects-against-root-kernel-exploits-dirty-cow nodetype--blog logged-out">
@@ -90,7 +90,7 @@
* page--node.html.twig
x page.html.twig
-->
<!-- BEGIN OUTPUT from 'modules/custom/clearlinux_org/themes/clearlinux_theme/templates/layout/page.html.twig' -->
<!-- BEGIN OUTPUT from 'modules/custom/clearlinux.github.io/themes/clearlinux_theme/templates/layout/page.html.twig' -->
<!-- ______________________ HEADER _______________________ -->
@@ -103,9 +103,9 @@
<div id="header__site_info">
<div class="header__site_img_wrapper">
<a href ="https://clearlinux.org/">
<img class="header__site_img_object" src="https://clearlinux.org/modules/custom/clearlinux_org/themes/clearlinux_theme/clear_linux_logo.svg" alt="Logo Clear Linux* Project"/>
<img class="header__site_txt_object" src="https://clearlinux.org/modules/custom/clearlinux_org/themes/clearlinux_theme/sass/components/layout/header/assets/clear-linux-text.svg" />
<a href ="https://clearlinux.github.io/">
<img class="header__site_img_object" src="https://clearlinux.github.io/modules/custom/clearlinux.github.io/themes/clearlinux_theme/clear_linux_logo.svg" alt="Logo Clear Linux* Project"/>
<img class="header__site_txt_object" src="https://clearlinux.github.io/modules/custom/clearlinux.github.io/themes/clearlinux_theme/sass/components/layout/header/assets/clear-linux-text.svg" />
</a>
</div>
</div>
@@ -119,7 +119,7 @@
<a tabindex='1' href="31103.html">Developer</a>
</li>
<li class="header__menu_list_item ">
<a tabindex='1' href="https://clearlinux.org/software">Software</a>
<a tabindex='1' href="https://clearlinux.github.io/software">Software</a>
</li>
</ul>
</nav>
@@ -181,7 +181,7 @@
x region--content.html.twig
* region.html.twig
-->
<!-- BEGIN OUTPUT from 'modules/custom/clearlinux_org/themes/clearlinux_theme/templates/layout/region--content.html.twig' -->
<!-- BEGIN OUTPUT from 'modules/custom/clearlinux.github.io/themes/clearlinux_theme/templates/layout/region--content.html.twig' -->
<!-- THEME DEBUG -->
@@ -207,15 +207,15 @@
x block--sharethis.html.twig
* block.html.twig
-->
<!-- BEGIN OUTPUT from 'modules/custom/clearlinux_org/themes/clearlinux_theme/templates/block/block--sharethis.html.twig' -->
<!-- BEGIN OUTPUT from 'modules/custom/clearlinux.github.io/themes/clearlinux_theme/templates/block/block--sharethis.html.twig' -->
<div id="block-sharethis" data-block-plugin-id="sharethis_block" class="block block-sharethis block-sharethis-block social_share">
<div class="sharethis-wrapper">
<a target="_blank" href="https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fclearlinux.org%2Fnews-blogs%2Fwhere-etcfstab-clear-linux&amp%3Bsrc=sdkpreparse" class="st_facebook_custom"></a>
<a target="_blank" href="https://twitter.com/intent/tweet?text=Clear%20Linux*%20Project&url=https%3A%2F%2Fclearlinux.org%2Fnews-blogs%2Fwhere-etcfstab-clear-linux" class="st_twitter_custom"></a>
<a target="_blank" href="https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fclearlinux.org%2Fnews-blogs%2Fwhere-etcfstab-clear-linux&title=Clear%20Linux*%20Project" class="st_linkedin_custom"></a>
<a target="_blank" href="https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fclearlinux.github.io%2Fnews-blogs%2Fwhere-etcfstab-clear-linux&amp%3Bsrc=sdkpreparse" class="st_facebook_custom"></a>
<a target="_blank" href="https://twitter.com/intent/tweet?text=Clear%20Linux*%20Project&url=https%3A%2F%2Fclearlinux.github.io%2Fnews-blogs%2Fwhere-etcfstab-clear-linux" class="st_twitter_custom"></a>
<a target="_blank" href="https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fclearlinux.github.io%2Fnews-blogs%2Fwhere-etcfstab-clear-linux&title=Clear%20Linux*%20Project" class="st_linkedin_custom"></a>
</div>
</div>
<!-- END OUTPUT from 'modules/custom/clearlinux_org/themes/clearlinux_theme/templates/block/block--sharethis.html.twig' -->
<!-- END OUTPUT from 'modules/custom/clearlinux.github.io/themes/clearlinux_theme/templates/block/block--sharethis.html.twig' -->
@@ -227,7 +227,7 @@
* block--system.html.twig
* block.html.twig
-->
<!-- BEGIN OUTPUT from 'modules/custom/clearlinux_org/themes/clearlinux_theme/templates/block/block--clearlinux-theme-content.html.twig' -->
<!-- BEGIN OUTPUT from 'modules/custom/clearlinux.github.io/themes/clearlinux_theme/templates/block/block--clearlinux-theme-content.html.twig' -->
<!-- THEME DEBUG -->
@@ -240,7 +240,7 @@
* node--full.html.twig
* node.html.twig
-->
<!-- BEGIN OUTPUT from 'modules/custom/clearlinux_org/themes/clearlinux_theme/templates/content/node--blog--full.html.twig' -->
<!-- BEGIN OUTPUT from 'modules/custom/clearlinux.github.io/themes/clearlinux_theme/templates/content/node--blog--full.html.twig' -->
<div class="blog_detail">
<div class="blog_detail__categories">
@@ -296,7 +296,7 @@
* field--text-with-summary.html.twig
* field.html.twig
-->
<!-- BEGIN OUTPUT from 'modules/custom/clearlinux_org/themes/clearlinux_theme/templates/field/field--node--body.html.twig' -->
<!-- BEGIN OUTPUT from 'modules/custom/clearlinux.github.io/themes/clearlinux_theme/templates/field/field--node--body.html.twig' -->
<div class="Text__description">
@@ -324,13 +324,13 @@
<p>The first figure below shows an example of the Dirty COW exploit using the standard Docker runtime. The second figure shows how Intel® VT effectively helps prevent escapes like Dirty COW from happening.</p>
<p><img alt="Dirty COW configuration 1" data-entity-type="" data-entity-uuid="" src="https://clearlinux.org/sites/default/files/dirtycowfig1.png" /></p>
<p><img alt="Dirty COW configuration 1" data-entity-type="" data-entity-uuid="" src="https://clearlinux.github.io/sites/default/files/dirtycowfig1.png" /></p>
<p>Figure 1: Docker using runc"</p>
<p> </p>
<p><img alt="Dirty COW configuration 2" data-entity-type="" data-entity-uuid="" src="https://clearlinux.org/sites/default/files/dirtycowfig2.png" /></p>
<p><img alt="Dirty COW configuration 2" data-entity-type="" data-entity-uuid="" src="https://clearlinux.github.io/sites/default/files/dirtycowfig2.png" /></p>
<p>Figure 2: Docker using Intel® Clear Containers</p>
@@ -338,7 +338,7 @@
<p>The guest page tables in each virtual machine instance isolate the guest OS memory location from the host OS. This type of segregation helps prevent undiscovered kernel exploits from allowing container-to-container escapes, and more importantly, container-to-host escapes like we saw in the Amazon example above.</p>
<p>The VM used for Intel® Clear Containers is optimized to make its memory footprint as lightweight as possible. Features like DAX, which removes the extra copy when accessing memory from a VM, are used to negate some of the resource penalties for using a VM. Other features like <em>qemu-lite</em> remove some PC-centric features, like BIOS support, that are not needed for running and protecting containers. You can read more about these optimizations at <a href="https://clearlinux.org/documentation/clear-containers.html">https://clearlinux.org/documentation/clear-containers.html</a>.</p>
<p>The VM used for Intel® Clear Containers is optimized to make its memory footprint as lightweight as possible. Features like DAX, which removes the extra copy when accessing memory from a VM, are used to negate some of the resource penalties for using a VM. Other features like <em>qemu-lite</em> remove some PC-centric features, like BIOS support, that are not needed for running and protecting containers. You can read more about these optimizations at <a href="https://clearlinux.github.io/documentation/clear-containers.html">https://clearlinux.github.io/documentation/clear-containers.html</a>.</p>
<p>The more intuitive security experts who read through the optimization features described in the link above might be wondering if container-to-container escapes might still be possible utilizing kernel samepage merging (KSM). The KSM feature works by identifying memory pages marked as mergeable that are exactly the same, discarding redundant copies, and having each process point to a single page. The good news is that after doing some testing we found that Intel® VT isolates container-to-container escapes through the extended page tables in such a way that a modified vDSO object in one Clear Container does not effect other Clear Containers. Intel tested and confirmed that modifying the vDSO object using the Dirty COW exploit inside of an Intel® Clear Container causes that container to point to the modified vDSO while other Intel® Clear Container instances still reference the original, unmodified, read only vDSO object. This effectively helps prevent container-to-container escapes.</p>
@@ -363,7 +363,7 @@
$ sudo nano /etc/systemd/system/docker.service.d/clr-containers.conf<br /><br />
[Service]<br />
ExecStart= ExecStart=/usr/bin/dockerd -D --add-runtime cor=/usr/bin/cc-oci-runtime --default-runtime=cor</code></li>
<li>Downgrade the Clear Container guest kernel to a version affected by Dirty COW: <code><span>$ cd /usr/share/clear-containers </span><br /><span>$ sudo wget <span>'</span></span><a class="external-link" href="https://download.clearlinux.org/releases/10000/clear/x86_64/os/Packages/clear-containers-image-9810-4.x86_64.rpm">https://download.clearlinux.org/releases/10000/clear/x86_64/os/Packages/clear-containers-image-9810-4.x86_64.rpm<span>'</span></a><br /><span>$ sudo rpm2cpio clear-containers-image-9810-4.x86_64.rpm | sudo cpio -idmv</span><br /><span>$ sudo rm -f clear-containers.img </span><br /><span>$ sudo mv ./usr/share/clear-containers/clear-* .</span><br /><span>$ sudo wget 'https://download.clearlinux.org/releases/10000/clear/x86_64/os/Packages/linux-container-4.5-49.x86_64.rpm' </span><br /><span>$ sudo rpm2cpio linux-container-4.5-49.x86_64.rpm | sudo cpio -idmv </span><br /><span>$ sudo rm -f linux-container-4.5-49.x86_64.rpm </span><br /><span>$ sudo cp ./usr/share/clear-containers/vmlinux-4.5-49.container ./ </span><br /><span>$ sudo rm -rf ./usr </span><br /><span>$ sudo rm -f vmlinux.container </span><br /><span>$ sudo ln -s vmlinux-4.5-49.container vmlinux.container</span></code></li>
<li>Downgrade the Clear Container guest kernel to a version affected by Dirty COW: <code><span>$ cd /usr/share/clear-containers </span><br /><span>$ sudo wget <span>'</span></span><a class="external-link" href="https://download.clearlinux.github.io/releases/10000/clear/x86_64/os/Packages/clear-containers-image-9810-4.x86_64.rpm">https://download.clearlinux.github.io/releases/10000/clear/x86_64/os/Packages/clear-containers-image-9810-4.x86_64.rpm<span>'</span></a><br /><span>$ sudo rpm2cpio clear-containers-image-9810-4.x86_64.rpm | sudo cpio -idmv</span><br /><span>$ sudo rm -f clear-containers.img </span><br /><span>$ sudo mv ./usr/share/clear-containers/clear-* .</span><br /><span>$ sudo wget 'https://download.clearlinux.github.io/releases/10000/clear/x86_64/os/Packages/linux-container-4.5-49.x86_64.rpm' </span><br /><span>$ sudo rpm2cpio linux-container-4.5-49.x86_64.rpm | sudo cpio -idmv </span><br /><span>$ sudo rm -f linux-container-4.5-49.x86_64.rpm </span><br /><span>$ sudo cp ./usr/share/clear-containers/vmlinux-4.5-49.container ./ </span><br /><span>$ sudo rm -rf ./usr </span><br /><span>$ sudo rm -f vmlinux.container </span><br /><span>$ sudo ln -s vmlinux-4.5-49.container vmlinux.container</span></code></li>
<li>Restart the Docker <em>systemd</em> service: <code>$ sudo systemctl daemon-reload<br />
$ sudo systemctl restart docker</code></li>
<li>Test that the Docker <em>runc</em> runtime and Clear Container <em>cor</em> runtime both work: <code>$ sudo docker run --rm -ti --runtime=runc ubuntu<br />
@@ -391,13 +391,13 @@
<p> </p>
<p><img alt="Dirty COW configuration 3" data-entity-type="" data-entity-uuid="" src="https://clearlinux.org/sites/default/files/dirtycowfig3.png" /></p>
<p><img alt="Dirty COW configuration 3" data-entity-type="" data-entity-uuid="" src="https://clearlinux.github.io/sites/default/files/dirtycowfig3.png" /></p>
<p>Figure 3: Docker runc container escape with Dirty COW</p>
<p> </p>
<p><img alt="Dirty COW configuration 4" data-entity-type="" data-entity-uuid="" src="https://clearlinux.org/sites/default/files/dirtycowfig4.png" /></p>
<p><img alt="Dirty COW configuration 4" data-entity-type="" data-entity-uuid="" src="https://clearlinux.github.io/sites/default/files/dirtycowfig4.png" /></p>
<p>Figure 4: Docker clear container runtime blocking of Dirty COW</p>
@@ -415,7 +415,7 @@
</ul>
</div>
<!-- END OUTPUT from 'modules/custom/clearlinux_org/themes/clearlinux_theme/templates/field/field--node--body.html.twig' -->
<!-- END OUTPUT from 'modules/custom/clearlinux.github.io/themes/clearlinux_theme/templates/field/field--node--body.html.twig' -->
@@ -427,15 +427,15 @@
<i class="fa fa-angle-up"> </i>
</a>
<!-- END OUTPUT from 'modules/custom/clearlinux_org/themes/clearlinux_theme/templates/content/node--blog--full.html.twig' -->
<!-- END OUTPUT from 'modules/custom/clearlinux.github.io/themes/clearlinux_theme/templates/content/node--blog--full.html.twig' -->
<!-- END OUTPUT from 'modules/custom/clearlinux_org/themes/clearlinux_theme/templates/block/block--clearlinux-theme-content.html.twig' -->
<!-- END OUTPUT from 'modules/custom/clearlinux.github.io/themes/clearlinux_theme/templates/block/block--clearlinux-theme-content.html.twig' -->
<!-- END OUTPUT from 'modules/custom/clearlinux_org/themes/clearlinux_theme/templates/layout/region--content.html.twig' -->
<!-- END OUTPUT from 'modules/custom/clearlinux.github.io/themes/clearlinux_theme/templates/layout/region--content.html.twig' -->
</main>
@@ -447,8 +447,8 @@
<div class="container padding-md--top-bottom padding-md--left-right">
<div class="footer__logo">
<div class="footer__logo__wrapper">
<img class="footer__site_img_object" src="https://clearlinux.org/modules/custom/clearlinux_org/themes/clearlinux_theme/clear_linux_logo.svg" alt="Logo Clear Linux* Project"/>
<img class="footer__site_txt_object" src="https://clearlinux.org/modules/custom/clearlinux_org/themes/clearlinux_theme/sass/components/layout/footer/assets/clear-linux-text-white.svg" />
<img class="footer__site_img_object" src="https://clearlinux.github.io/modules/custom/clearlinux.github.io/themes/clearlinux_theme/clear_linux_logo.svg" alt="Logo Clear Linux* Project"/>
<img class="footer__site_txt_object" src="https://clearlinux.github.io/modules/custom/clearlinux.github.io/themes/clearlinux_theme/sass/components/layout/footer/assets/clear-linux-text-white.svg" />
</div>
</div>
<div class="footer__details">
@@ -465,7 +465,7 @@
<a target="_blank" tabindex='1' href="http://twitter.com/clearlinux" title="Twitter"><i class="fa "></i></a>
</li>
<li class="footer__social_media__list_item">
<a target="_blank" tabindex='1' href="https://community.clearlinux.org/" title="Discourse"><i class="fa "></i></a>
<a target="_blank" tabindex='1' href="https://community.clearlinux.github.io/" title="Discourse"><i class="fa "></i></a>
</li>
</ul>
</div>
@@ -497,7 +497,7 @@
</div>
</footer>
<!-- END OUTPUT from 'modules/custom/clearlinux_org/themes/clearlinux_theme/templates/layout/page.html.twig' -->
<!-- END OUTPUT from 'modules/custom/clearlinux.github.io/themes/clearlinux_theme/templates/layout/page.html.twig' -->
</div>
@@ -506,23 +506,23 @@
<script src="https://clearlinux.org/core/assets/vendor/jquery/jquery.min.js?v=3.6.0"></script>
<script src="https://clearlinux.org/core/misc/polyfills/element.matches.js?v=9.4.8"></script>
<script src="https://clearlinux.org/core/assets/vendor/once/once.min.js?v=1.0.1"></script>
<script src="https://clearlinux.org/modules/contrib/extlink/extlink.js?v=9.4.8"></script>
<script src="https://clearlinux.org/modules/contrib/google_analytics/js/google_analytics.js?v=9.4.8"></script>
<script src="https://clearlinux.github.io/core/assets/vendor/jquery/jquery.min.js?v=3.6.0"></script>
<script src="https://clearlinux.github.io/core/misc/polyfills/element.matches.js?v=9.4.8"></script>
<script src="https://clearlinux.github.io/core/assets/vendor/once/once.min.js?v=1.0.1"></script>
<script src="https://clearlinux.github.io/modules/contrib/extlink/extlink.js?v=9.4.8"></script>
<script src="https://clearlinux.github.io/modules/contrib/google_analytics/js/google_analytics.js?v=9.4.8"></script>
<script src="https://cdnjs.cloudflare.com/ajax/libs/OwlCarousel2/2.2.1/owl.carousel.min.js" integrity="sha256-s5TTOyp+xlSmsDfr/aZhg0Gz+JejYr5iTJI8JxG1SkM=" crossorigin="anonymous"></script>
<script src="https://clearlinux.org/modules/custom/clearlinux_org/themes/clearlinux_theme/js/src/jquery.colorbox.min.js?v=9.4.8"></script>
<script src="https://clearlinux.org/modules/custom/clearlinux_org/themes/clearlinux_theme/js/src/clearlinux_theme.js?v=9.4.8"></script>
<script src="https://clearlinux.org/modules/custom/clearlinux_org/themes/clearlinux_theme/bower_components/clipboard/dist/clipboard.min.js?v=9.4.8"></script>
<script src="https://clearlinux.org/core/assets/vendor/js-cookie/js.cookie.min.js?v=3.0.1"></script>
<script src="https://clearlinux.org/modules/contrib/eu_cookie_compliance/js/eu_cookie_compliance.min.js?v=9.4.8" defer></script>
<script src="https://clearlinux.org/modules/custom/clearlinux_org/themes/clearlinux_theme/js/dist/layout/header/header.js?rl3r25"></script>
<script src="https://clearlinux.org/libraries/codesnippet/lib/highlight/highlight.pack.js?v=9.4.8"></script>
<script src="https://clearlinux.org/modules/contrib/codesnippet/js/codesnippet.js?v=9.4.8"></script>
<script src="https://clearlinux.github.io/modules/custom/clearlinux.github.io/themes/clearlinux_theme/js/src/jquery.colorbox.min.js?v=9.4.8"></script>
<script src="https://clearlinux.github.io/modules/custom/clearlinux.github.io/themes/clearlinux_theme/js/src/clearlinux_theme.js?v=9.4.8"></script>
<script src="https://clearlinux.github.io/modules/custom/clearlinux.github.io/themes/clearlinux_theme/bower_components/clipboard/dist/clipboard.min.js?v=9.4.8"></script>
<script src="https://clearlinux.github.io/core/assets/vendor/js-cookie/js.cookie.min.js?v=3.0.1"></script>
<script src="https://clearlinux.github.io/modules/contrib/eu_cookie_compliance/js/eu_cookie_compliance.min.js?v=9.4.8" defer></script>
<script src="https://clearlinux.github.io/modules/custom/clearlinux.github.io/themes/clearlinux_theme/js/dist/layout/header/header.js?rl3r25"></script>
<script src="https://clearlinux.github.io/libraries/codesnippet/lib/highlight/highlight.pack.js?v=9.4.8"></script>
<script src="https://clearlinux.github.io/modules/contrib/codesnippet/js/codesnippet.js?v=9.4.8"></script>
</body>
</html>
<!-- END OUTPUT from 'modules/custom/clearlinux_org/themes/clearlinux_theme/templates/layout/html.html.twig' -->
<!-- END OUTPUT from 'modules/custom/clearlinux.github.io/themes/clearlinux_theme/templates/layout/html.html.twig' -->