aboutsummaryrefslogtreecommitdiffstats
path: root/releasenotes/notes/disable-core-dump-for-setuid-programs-e83a2a5da908b9c3.yaml
AgeCommit message (Collapse)AuthorFilesLines
2017-03-28Disable core dump for setuid programszshi1-0/+12
The core dump of a setuid program is more likely to contain sensitive data, as the program itself runs with greater privileges than the user who initiated execution of the program. Disabling the ability for any setuid program to write a core file decreases the risk of unauthorized access of such data. This change sets core dump for setuid programs to '0'. Change-Id: Ib05d993c1bb59b59c784e438f805733f636c743d Signed-off-by: zshi <zshi@redhat.com>