[$] The difficulty of safe path traversal

Aleksa Sarai, as the maintainer of the

https://github.com/opencontainers/runc?tab=readme-ov-file#runc

, faces a

constant battle against security problems. Recently, runc has seen

another

instance of a security vulnerability that can be traced back to the difficulty

of handling file paths on Linux. Sarai spoke at the 2025

https://lpc.events/event/19

(https://lpc.events/event/19/contributions/2065/attachments/1851/3964/Path%20Safety%20in%20the%20Trenches%20%5BLPC%202025%5D.pdf

;

video)

about

some of the problems runc has had with path-traversal vulnerabilities, and to

ask people to please use

libpathrs, the library that he has been developing for

safe path traversal.

https://lwn.net/Articles/1050887/

Reply to this note

Please Login to reply.

Discussion

No replies yet.