• N.E.P.T.R
    link
    fedilink
    English
    arrow-up
    1
    ·
    4 hours ago

    Firejail is a large SETUID binary which can (and has) aid in privilege escalation. It is recommended to avoid it for this reason.

    See: https://madaidans-insecurities.github.io/linux.html#firejail

    If you are relying on community sandboxing profiles and not making your own, i can understand why Firejail is interesting as a choice because of its large community.

    If you are making your own, consider checking out Bubblewrap (available on most Linux systems), Bubblejail), Crablock, and Sydbox, which all use unprivileged sandboxes.