Summary: | jails mishandle the default lo0 127.0.0.1 loopback interface | ||
---|---|---|---|
Product: | Base System | Reporter: | Joe Barbish <qjail1> |
Component: | kern | Assignee: | freebsd-jail (Nobody) <jail> |
Status: | New --- | ||
Severity: | Affects Many People | CC: | crest, dch, jamie, me, pat, zlei |
Priority: | --- | ||
Version: | 10.3-RELEASE | ||
Hardware: | Any | ||
OS: | Any |
Description
Joe Barbish
2016-06-05 13:19:00 UTC
Alias jails map 127.0.0.1 and Or we should document this security issue in the **BUGS** section before a final fix ? Alias jails map 127.0.0.1 (and ::1) to their primary alias IP address per address family. This can be quite useful to intentionally expose a service bound to a changing IP address per launch, but it can also expose services that are only meant to listen to the loopback address which a jail with alias networking doesn't have unless the loopback address is one of its alias IP addresses. Documenting this behaviour more prominently is the best we can do without breaking this double-edged feature. |