Elektrine lite

← Feed

@hirihit640@sh.itjust.works

Post #3794829

2026-07-06 05:36 UTC

Got it. Access to docker.sock is definitely something to be wary of, or CAP_ADMIN, or access to certain host devices. Worth mentioning though that Jellyfin usually has none of these.

Replies (1)

  • @erev@lemmy.world 2026-07-06 07:15

    Also worth mentioning that Linux recently has had two massive privilege escalation vulnerabilities that bypass system namespacing and thus also provide container escapes.

    Open ##3794828