Setting NoNewPrivs system wide as default (osc26) episode artwork

EPISODE · Jun 26, 2026 · 27 MIN

Setting NoNewPrivs system wide as default (osc26)

from Chaos Computer Club - recent events feed (high quality) · host Thorsten Kukuk

Setuid binaries are not dangerous in themselves, but a rather worthwhile target that can lead to privilege escalation if they have a vulnerability. The goal is therefore to eliminate this attack surface. The kernel provides a solution with the no_new_privs flag, which effectively disables setuid/setgid bits and file capabilities. This flag can be set with systemd and the NoNewPrivs option in Pid1. In this talk I will present how this can be reached, what the current status is and where are the remaining problems are. about this event: https://c3voc.de

Episode metadata supplied by the publisher feed · Published Jun 26, 2026

Embed this episode

Ready to play

Setting NoNewPrivs system wide as default (osc26)

0:00 27:41

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Chaos Computer Club - recent events feed (high quality)?

This episode is 27 minutes long.

When was this Chaos Computer Club - recent events feed (high quality) episode published?

This episode was published on June 26, 2026.

Can I download this Chaos Computer Club - recent events feed (high quality) episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!