- 1 Post
- 2 Comments
Joined 8 months ago
Cake day: February 10th, 2026
You are not logged in. If you use a Fediverse account that is able to follow users, you can follow this user.
zazarpro@lemmy.mlto
Linux@lemmy.ml•Is it possible to use a virtual machine to more safely run pirated games on linux?English
1·3 months agoJust so you know Firejail is a setuid root binary with a lot of code. This means that if that code gets exploited and the sandboxed process escapes the sandbox it will have root privileges instead of the running users.
Sources: https://github.com/netblue30/firejail, https://madaidans-insecurities.github.io/linux.html#firejail

Yes, however, it won’t prevent the process launching as root because firejail is setuid. This means that the person executing the file transitions into the privileges of the owner of the file, in this case, root. Since this root process remains in the background it can theoretically be exploited by the sandboxed process that firejail spawns.
The odds of this happening to someone who isn’t getting targeted are very very low so using firejail is still alright, but you should consider a non-setuid solution like bubblewrap or just a VM.