HashiCorp Nomad and Nomad Enterprise did not enforce the allowprivileged restriction for the Docker task driver's host namespace mode options. This may allow an authenticated job submitter to run a container in a host namespace and access information belonging to the host or to other workloads on the same client. This vulnerability, CVE-2026-14373, is fixed in Nomad Community Edition 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14.
HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job submitter to bind-mount a host path into a container even when volume bind mounts are disabled, potentially leading to reading and writing files on the host. This vulnerability, CVE-2026-14891, is fixed in Nomad Community Edition 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14.
HashiCorp Nomad and Nomad Enterprise are vulnerable to a cross-namespace authorization bypass in the dynamic host volumes feature that may allow an operator holding the host volume delete permission in one namespace to delete a sticky volume claim belonging to a job in another namespace. This vulnerability, CVE-2026-14896, is fixed in Nomad Community Edition 2.0.4 and Nomad Enterprise 2.0.4, 1.11.8, and 1.10.14.
HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on the client host through a path traversal attack. This vulnerability (CVE-2026-7474) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.
HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-6959) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.
HashiCorp Nomad and Nomad Enterprise 1.5.13 up to 1.6.6, and 1.7.3 template renderer is vulnerable to arbitrary file write on the host as the Nomad client user through symlink attacks. Fixed in Nomad 1.7.4, 1.6.7, 1.5.14.
A vulnerability was identified in Nomad such that the search HTTP API can reveal names of available CSI plugins to unauthenticated users or users without the plugin:read policy. This vulnerability, CVE-2023-3300, affects Nomad since 0.11 and was fixed in 1.6.0, 1.5.7, and 1.4.11.
A vulnerability was identified in Nomad such that the API caller’s ACL token secret ID is exposed to Sentinel policies. This vulnerability, CVE-2023-3299, affects Nomad from 1.2.11 up to 1.5.6, and 1.4.10 and was fixed in 1.6.0, 1.5.7, and 1.4.11.
A vulnerability was identified in Nomad, an ACL policy using a block without label may be applied to unexpected resources. This vulnerability, CVE-2023-3072, affects Nomad from 0.7 up to 1.5.6 and 1.4.10 and was fixed in 1.6.0, 1.5.7, and 1.4.11.
HashiCorp Nomad and Nomad Enterprise 1.0.2 up to 1.2.12, and 1.3.5 jobs submitted with an artifact stanza using invalid S3 or GCS URLs can be used to crash client agents. Fixed in 1.2.13, 1.3.6, and 1.4.0.
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 workload identity token can list non-sensitive metadata for paths under nomad/ that belong to other jobs in the same namespace. Fixed in 1.4.2.
HashiCorp Nomad and Nomad Enterprise 1.4.0 up to 1.4.1 event stream subscribers using a token with TTL receive updates until token garbage is collected. Fixed in 1.4.2.
HashiCorp Nomad and Nomad Enterprise 1.1.1 through 1.1.5 allowed authenticated users with job submission capabilities to cause denial of service by submitting incomplete job specifications with a Consul mesh gateway and host networking mode. Fixed in 1.1.6.
HashiCorp Nomad and Nomad Enterprise up to 0.12.9 exec and java task drivers can access processes associated with other tasks on the same node. Fixed in 0.12.10, and 1.0.3.
HashiCorp Nomad and Nomad Enterprise Raft RPC layer allows non-server agents with a valid certificate signed by the same CA to access server-only functionality, enabling privilege escalation. Fixed in 1.0.10 and 1.1.4.
HashiCorp Nomad and Nomad Enterprise up to 0.10.2 incorrectly validated role/region associated with TLS certificates used for mTLS RPC, and were susceptible to privilege escalation. Fixed in 0.10.3.
HashiCorp Nomad and Nomad Enterprise before 0.10.3 allow unbounded resource usage.
Specific Go Packages Affected github.com/hashicorp/nomad/command/agent
HashiCorp Nomad and Nomad Enterprise 1.6.12 up to 1.7.9, and 1.8.1 archive unpacking during migration is vulnerable to path escaping of the allocation directory. This vulnerability, CVE-2024-6717, is fixed in Nomad 1.6.13, 1.7.10, and 1.8.2.
Nomad Community and Nomad Enterprise ("Nomad") volume specification is vulnerable to arbitrary cross-namespace volume creation through unauthorized Container Storage Interface (CSI) volume writes. This vulnerability, identified as CVE-2024-10975, is fixed in Nomad Community Edition 1.9.2 and Nomad Enterprise 1.9.2, 1.8.7, and 1.7.15.
In HashiCorp Nomad and Nomad Enterprise from 0.6.1 up to 1.6.13, 1.7.10, and 1.8.2, the archive unpacking process is vulnerable to writes outside the allocation directory during migration of allocation directories when multiple archive headers target the same file. This vulnerability, CVE-2024-7625, is fixed in Nomad 1.6.14, 1.7.11, and 1.8.3. Access or compromise of the Nomad client agent at the source allocation first is a prerequisite for leveraging this vulnerability.
Nomad Community and Nomad Enterprise (“Nomad”) prefix-based ACL policy lookup can lead to incorrect rule application and shadowing. This vulnerability, identified as CVE-2025-4922, is fixed in Nomad Community Edition 1.10.2 and Nomad Enterprise 1.10.2, 1.9.10, and 1.8.14.
Nomad Community and Nomad Enterprise (“Nomad”) are vulnerable to unintentional exposure of the workload identity token and client secret token in audit logs. This vulnerability, identified as CVE-2025-1296, is fixed in Nomad Community Edition 1.9.7 and Nomad Enterprise 1.9.7, 1.8.11, and 1.7.19.
Nomad Community and Nomad Enterprise ("Nomad") event stream configured with a wildcard namespace can bypass the ACL Policy allowing reads on other namespaces.
Nomad Community and Nomad Enterprise ("Nomad") allocations are vulnerable to privilege escalation within a namespace through unredacted workload identity tokens. This vulnerability, identified as CVE-2024-12678, is fixed in Nomad Community Edition 1.9.4 and Nomad Enterprise 1.9.4, 1.8.8, and 1.7.16.
Latest version: 1.11.3
HCL Nomad server on Domino is vulnerable to the cache containing sensitive information which could potentially give an attacker the ability to acquire the sensitive information.
HCL Nomad server on Domino did not configure certain HTTP Security headers by default which could allow an attacker to obtain sensitive information via unspecified vectors.
Here is the fifth Landlock newsletter!
Official website: https://landlock.io Previews newsletter: https://lore.kernel.org/landlock/20240716.yui4Iezai8ae () digikod net/
TL;DR: Check your sandboxed programs with Linux 6.15, review the audit logs, and update the sandbox policy if you see any Landlock events.
Kernel features ===============
Restricting signals and abstract UNIX sockets ---------------------------------------------
Linux 6.12 (Landlock ABI 6) introduces IPC scoping with a new ruleset "scoped" field, thanks to Tahera Fahimi. This field accepts a set of flags: the LANDLOCKSCOPEABSTRACTUNIXSOCKET flag denies connections to abstract UNIX sockets created outside the current scoped domain, and the LANDLOCKSCOPESIGNAL flag denies sending signals to processes outside the current scoped domain.
These restrictions also apply to nested domains according to their scope. Both features have been requested to help isolate untrusted processes, making it easier to protect against related threats. These changes will also be useful for supporting other kinds of IPC isolation.
See user space documentation: https://docs.kernel.org/userspace-api/landlock.html#scope-flags
Audit logging for denied access requests ----------------------------------------
Linux 6.15 (Landlock ABI 7) adds the ability to log denied requests with audit. This provides visibility into why access requests are denied, including the origin of the security policy, missing access rights, and object descriptions.
The logging system is designed to minimize log spam while still alerting about unexpected blocked access. Being able to see what is denied, and more importantly why, is a crucial feature for any security mechanism. The default behavior alerts about unexpected access requests (i.e., attacks) while ignoring noise from programs unaware they are sandboxed. Tailored sandboxing can adjust this behavior with the three new LANDLOCKRESTRICTSELFLOG flags, though this should not be necessary in most cases.
This new Landlock capability is the most significant change since Landlock was merged into mainline: +46% SLOC for the kernel and +23% SLOC for kselftests. See sysadmin and user space documentation: https://docs.kernel.org/admin-guide/LSM/landlock.html#audit https://docs.kernel.org/userspace-api/landlock.html#c.syslandlockrestrictself
Kernel fixes ============
All stable kernels supporting Landlock now also provide a new interface to probe for user-visible fixes. This may be required by some Landlock libraries to safely expose more Landlock features on up-to-date kernels. This improvement in the quality of the Landlock specification should not be noticed by most users.
The first issue fixed by an erratum is related to TCP socket identification. Mikhail Ivanov fixed an issue where IPv4 and IPv6 stream sockets (e.g., SMC, MPTCP, or SCTP) were incorrectly restricted by TCP access rights during bind(2) and connect(2) operations. This change ensures that only TCP sockets are subject to TCP access rights, allowing other protocols to operate without unnecessary restrictions.
The second erratum is related to scoped signal handling. This fix addresses an issue where signal scoping was overly restrictive, preventing sandboxed threads from signaling other threads within the same process if they belonged to different domains. Because threads are not security boundaries, user space might assume that all thread within the same process can send signals between themselves (see nptl(7) and libpsx(3)). Consistent with ptrace(2) behavior, direct interaction between threads of the same process should always be allowed. This change ensures that any thread is allowed to send signals to any other thread within the same process, regardless of their domain.
Landlock libraries ==================
The Landlock crate and Go library have been updated, bringing support for the latest Landlock features, improved documentation, and better tests: https://github.com/landlock-lsm/rust-landlock/blob/main/CHANGELOG.md#v042
Go-Landlock is now packaged in Debian: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1096137
Please update your dependencies and use the latest Landlock ABI version for improved sandboxing.
Landlock logo =============
Landlock now has a logo! Guess what it means. ;) Feel free to use it to illustrate Landlock. https://github.com/landlock-lsm/landlock-logo
Talks and articles ==================
Günther Noack gave a talk at the Linux Security Summit Europe titled "Update On Landlock IOCTL Support": https://lsseu2024.sched.com/event/1ebVW He explains how Landlock works and why it was designed this way. He then discusses the challenges of implementing a useful and practical IOCTL control, and finally introduces ongoing work to improve Landlock.
I gave a talk at the Open Source Summit Europe on "Linux Sandboxing with Landlock": https://osseu2024.sched.com/event/1ej3a This was an introduction to Landlock, including why and how it should be used to secure user environments.
Tahera Fahimi participated in a panel discussion at the Open Source Summit Europe, where she talked about her Outreachy internship working on Landlock: https://osseu2024.sched.com/event/1ej1w
I also gave a talk at FOSDEM about Sandbox IDs with Landlock: https://fosdem.org/2025/schedule/event/fosdem-2025-6071-sandbox-ids-with-landlock/ This talk explains the properties of Landlock IDs, how they are used in audit, and how they could be used to identify a set of processes, such as a container.
I updated the Landlock workshop to demonstrate sandboxing with ImageMagick: https://github.com/landlock-lsm/workshop-imagemagick https://landlock.io/talks/2025-01-29landlock-workshop.pdf
I was invited to present Landlock at the Compartmentalization Community meeting: https://drive.google.com/drive/folders/129kNPaTriApmdRU4OFwl3KwDYJlIXLEH (see Eval & Benchmarking meeting of 2025-04-24)
An interesting article about sandboxing was published on the Emilua (Lua runtime) blog: https://blog.emilua.org/2025/01/12/software-sandboxing-basics/
Rémi Gacogne will give a talk at Pass the Salt about sandboxing Pacman: https://cfp.pass-the-salt.org/pts2025/talk/FUL7LS/
Documentation and examples ==========================
Günther Noack is writing documentation with use cases for Landlock. We'll move this documentation to the official website when ready but in the meantime it's worth a read! https://wiki.gnoack.org/UsingLandlock https://github.com/gnoack/landlock-examples
New Linux distributions support ===============================
GNOME OS's kernel has Landlock enabled by default (it's been a while, but we missed it): https://gitlab.gnome.org/GNOME/gnome-build-meta/-/mergerequests/2559
Flatcar's kernel has had Landlock enabled by default since last year: https://github.com/flatcar/scripts/pull/2158
Red Hat Enterprise Linux 9.6.0 (RHEL) has enabled Landlock by default and also backported features up to Landlock ABI 5, thanks to Ryan Sullivan and Red Hat reviewers: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-9/-/commit/9039cec1ed523025381bdbc62cb924601be5059b It is available since kernel-5.14.0-568.el9: https://gitlab.com/redhat/centos-stream/src/kernel/centos-stream-9/-/commit/5ba435c29b4704e87af1a0fd291ea6610ff5af92 CentOS Stream, Rocky Linux, and other RHEL alternatives should also gain the same support: https://bugs.rockylinux.org/view.php?id=7987
New Landlock user space support ===============================
GNOME's tracker-extract is now sandboxed with Landlock (it's been a while, but it wasn't mentioned in a previous newsletter): https://gitlab.gnome.org/GNOME/localsearch/-/mergerequests/499 Support was merged in GNOME 46: https://gitlab.gnome.org/Teams/Websites/release.gnome.org/-/issues/37 There were some interesting compatibility issues that have since been fixed: https://gitlab.gnome.org/GNOME/localsearch/-/issues/319#note2046228 All these issues can be avoided by using a Landlock library with best-effort support (Rust or Go for now).
HashiCorp's Nomad can now run sandboxed processes with Landlock: https://developer.hashicorp.com/nomad/plugins/drivers/exec2
Unblob 24.12.4 has gained support for Landlock: https://github.com/onekey-sec/unblob/pull/1022
dosemu2 has gained support for Landlock: https://github.com/dosemu2/dosemu2/pull/2344
wireproxy 1.0.8 has gained support for Landlock: https://github.com/pufferffish/wireproxy/pull/108
Landrun is a new sandboxing tool leveraging Landlock: https://github.com/Zouuup/landrun https://news.ycombinator.com/item?id=43445662
Ongoing work ============
Ongoing kernel work can be tracked here: https://github.com/orgs/landlock-lsm/projects/1
It would be good to have guidelines to help developers sandbox their applications. OpenSSF Working Groups could be a good place for that: https://github.com/ossf/wg-best-practices-os-developers/issues/631 Any help would be appreciated.
We are working on a Landlock configuration format to empower all Linux users to sandbox their applications with Landlock: https://github.com/landlock-lsm/landlockconfig A new tool will make this library easy to use.
Thanks to all contributors!
Regards, Mickaël