···267267 <itemizedlist>
268268 <listitem><para>User namespaces require <literal>CAP_SYS_ADMIN</literal>:
269269 consequently, unprivileged namespaces are unsupported. Applications that
270270- rely on namespaces for sandboxing (e.g., chromium) must use a privileged
271271- helper.</para></listitem>
270270+ rely on namespaces for sandboxing must use a privileged helper. For chromium
271271+ there is <option>security.chromiumSuidSandbox.enable</option>.</para></listitem>
272272273273 <listitem><para>Access to EFI runtime services is disabled by default:
274274 this plugs a potential code injection attack vector; use