{
  "id": 8565542,
  "title": "Landlock LSM: Secure Sandboxing directly in the Kernel",
  "url": "https://urgent.news/2026/09/20/landlock-lsm-secure-sandboxing-direkt-im-kernel",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-20T00:00:30.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/uhltak/landlock-lsm-secure-sandboxing-direkt-im-kernel-1gjf"
  },
  "original_language": "de",
  "account": "Landlock is a Mandatory Access Control (MAC) solution available in Linux kernel 5.13 and later. It allows users to define their own sandboxes and restrict running programs without needing administrative rights. Landlock adds an extra layer of security, enabling users to limit access to specific paths in the file system, even if a process is compromised. Tools like Firejail already utilize Landlock, providing a practical way to use this technology, such as opening suspicious files or executing download tools in a secure environment.",
  "summary": "Landlock LSM: Die unsichtbare Festung für deine Linux-Apps Stell dir vor, dein Browser wird kompromittiert. Ein klassischer Zero-Day-Exploit, eine schadhafte JavaScript-Funktion in einem Werbenetzwerk – und plötzlich sitzt ein Angreifer an den Tasten deiner Shell. In der traditionellen Linux-Welt ist das oft das Ende des Weges. Der Prozess läuft mit deinen User-Rechten, er hat Zugriff auf dein…",
  "key_points": [],
  "editors_take": "Landlock LSM shifts Linux security by enabling users to set custom sandbox rules, limiting damage from compromised applications, without needing administrative privileges or complex policy languages.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}