This executable is calling setuid and setgid without setgroups or initgroups.
This means it didn't relinquish all groups, and this would be a potential security issue.
While packaging cagebreak for openSUSE, this was caught by the rpm linter.
I can't validate the concerns myself, please check POS36-C for more in-depth
information.
Related:
swaywm/sway#884
WayfireWM/wayfire#696
While packaging cagebreak for openSUSE, this was caught by the rpm linter.
I can't validate the concerns myself, please check POS36-C for more in-depth
information.
Related:
swaywm/sway#884
WayfireWM/wayfire#696