openSUSE Leap 16.1 adds an immutable mode with a read-only, transactionally updated root filesystem, bringing Leap Micro's model into the stable release. Container and edge teams can get that from the Leap they already run if they pick it at install.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+25
- Incentives35
- Confidence55
buildOne report1 publisher A dev.to write-up argues that Landlock's unprivileged self-confinement retires the profile-maintenance tax that AppArmor and SELinux impose, though the rules it describes are still paths, so somebody has to enumerate them.
Reality
- Evidence24
- Adoption20
- Hype gap+45
- Incentives62
- Confidence28
A researcher posting to oss-security reports that all four proof-of-concept exploits gave an unprivileged local user root code execution on the test targets, against kernel code that has been in the tree for between 10 and 21 years.
Publishers:scour.ing
Reality
- Evidence66
- Adoption35
- Hype gap−10
- Incentives28
- Confidence62
buildOne report1 publisher Landlock has been in mainline since kernel 5.13 and needs no policy file and no administrator to confine a process to named paths. The dev.to walkthrough explaining it leaves the enforcing syscall inside a comment.
Reality
- Evidence30
- Adoption35
- Hype gap+45
- Incentives30
- Confidence45
buildOne report1 publisher A dev.to write-up traces a build that fails only on enterprise-kernel servers to three correct components meeting badly. The seccomp profile that fixes it stays inert until the build runs on Docker's classic engine.
Reality
- Evidence50
- Adoption12
- Hype gap−15
- Incentives55
- Confidence55
buildOne report1 publisher Landlock has been in mainline Linux since 5.13 and asks no administrator for permission. The dev.to walkthrough that demonstrates it prints a read-only rule under a goal that requires writing.
Reality
- Evidence32
- Adoption
- Insufficient
- Hype gap+40
- Incentives20
- Confidence58
buildOne report1 publisher CISA added CVE-2026-53362 to its exploited-vulnerabilities catalog on August 27. The single published account of the bug says the escape needs only unprivileged code on the node plus permission to open a UDP socket, which almost nothing is denied.
Reality
- Evidence20
- Adoption12
- Hype gap+40
- Incentives55
- Confidence30
Sysdig counts 19 security-relevant changes in the release. The ones that arrive switched on, led by SELinuxMount at stable, are the ones that can break a running cluster.
Reality
- Evidence58
- Adoption30
- Hype gap+10
- Incentives68
- Confidence54