Unchecked nil eBPF Map Dereference in UpdateContainerRules Causes Daemon Crash
There is a bug in UpdateContainerRules where failure to create a container inner map (Map == nil) results in a nil pointer dereference panic, causing the KubeArmor daemon to crash. This happens when ebpf.NewMap fails due to limits like ENOMEM or eBPF subsystem map limits. The fix is to verify that be.ContainerMap[id].Map is non-nil before proceeding with policy updates.
0 条评论