diff --git a/config/apparmor/abstractions/container-base.in b/config/apparmor/abstractions/container-base.in index 1a3ead89a..2606fb64c 100644 --- a/config/apparmor/abstractions/container-base.in +++ b/config/apparmor/abstractions/container-base.in @@ -73,6 +73,7 @@ # block some other dangerous paths deny @{PROC}/kcore rwklx, deny @{PROC}/sysrq-trigger rwklx, + deny @{PROC}/acpi/** rwklx, # deny writes in /sys except for /sys/fs/cgroup, also allow # fusectl, securityfs and debugfs to be mounted there (read-only)