{
  "id": 7902145,
  "title": "Landlock LSM: Secure Linux Apps without Root Privileges",
  "url": "https://urgent.news/2026/09/17/landlock-lsm-secure-linux-apps-ohne-root-rechte",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-17T00:00:19.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/uhltak/landlock-lsm-secure-linux-apps-ohne-root-rechte-17o"
  },
  "original_language": "de",
  "account": "The Linux kernel's Landlock LSM feature allows users to create sandbox policies for applications without requiring root privileges. This Mandatory Access Control technology enables users to restrict file and network access for applications, providing a more secure way to run programs. With Landlock, users can create custom sandbox policies using tools like landconfine, limiting an application's access to specific files and network resources. The feature has been enhanced in kernel 6.3 to include network permissions, allowing for more comprehensive sandboxing.",
  "summary": "Der Artikel von Dev.to erklärt das neue Feature Landlock LSM im Linux-Kernel, das es ermöglicht, Programme sicher einzuschränken, ohne root-Rechte zu benötigen. Landlock ist eine Mandatory Access Control (MAC)-Technologie, die als Loadable Security Module (LSM) integriert ist und jedem Benutzer ermöglicht, eigene Sandbox-Richtlinien zu erstellen, um die Zugriffsrechte einer Anwendung auf Dateien und Netzwerkressourcen zu beschränken. Der Artikel hebt das Potenzial von Landlock hervor, ein revolutionäres Paradigma für die Sicherheit in Linux-Umgebungen zu schaffen, da es die Komplexität und die Notwendigkeit von root-Rechten beseitigt, die typischerweise mit herkömmlichen Sandboxing-Lösungen verbunden sind.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}