diff options
Diffstat (limited to 'net/core/sysctl_net_core.c')
| -rw-r--r-- | net/core/sysctl_net_core.c | 5 | 
1 files changed, 5 insertions, 0 deletions
diff --git a/net/core/sysctl_net_core.c b/net/core/sysctl_net_core.c index a7c36845b12..d1b08045a9d 100644 --- a/net/core/sysctl_net_core.c +++ b/net/core/sysctl_net_core.c @@ -216,6 +216,11 @@ static __net_init int sysctl_core_net_init(struct net *net)  			goto err_dup;  		tbl[0].data = &net->core.sysctl_somaxconn; + +		/* Don't export any sysctls to unprivileged users */ +		if (net->user_ns != &init_user_ns) { +			tbl[0].procname = NULL; +		}  	}  	net->core.sysctl_hdr = register_net_sysctl(net, "net/core", tbl);  |