Gate setid transitions to limit CAP_SET{U/G}ID capabilities
modulename: safesetid.ko
configname: CONFIG_SECURITY_SAFESETID
Linux Kernel Configuration
└─>Security options
└─>Gate setid transitions to limit CAP_SET{U/G}ID capabilities
In linux kernel since version 5.1 (release Date: 2019-05-05)
SafeSetID is an LSM module that gates the setid family of syscalls to
restrict UID/GID transitions from a given UID/GID to only those
approved by a system-wide whitelist. These restrictions also prohibit
the given UIDs/GIDs from obtaining auxiliary privileges associated
with CAP_SET{U/G}ID, such as allowing a user to set up user namespace
UID mappings.
If you are unsure how to answer this question, answer N.
restrict UID/GID transitions from a given UID/GID to only those
approved by a system-wide whitelist. These restrictions also prohibit
the given UIDs/GIDs from obtaining auxiliary privileges associated
with CAP_SET{U/G}ID, such as allowing a user to set up user namespace
UID mappings.
If you are unsure how to answer this question, answer N.