diff --git a/profiles/seccomp/default.json b/profiles/seccomp/default.json index 4213799ddb..786e5658ff 100644 --- a/profiles/seccomp/default.json +++ b/profiles/seccomp/default.json @@ -401,6 +401,8 @@ }, { "names": [ + "process_vm_readv", + "process_vm_writev", "ptrace" ], "action": "SCMP_ACT_ALLOW", diff --git a/profiles/seccomp/default_linux.go b/profiles/seccomp/default_linux.go index 879eb88c64..32778e5116 100644 --- a/profiles/seccomp/default_linux.go +++ b/profiles/seccomp/default_linux.go @@ -390,7 +390,11 @@ func DefaultProfile() *Seccomp { Args: []*specs.LinuxSeccompArg{}, }, { - Names: []string{"ptrace"}, + Names: []string{ + "process_vm_readv", + "process_vm_writev", + "ptrace", + }, Action: specs.ActAllow, Includes: Filter{ MinKernel: &KernelVersion{4, 8},