Package: systemd
Version: 234-3~bpo9+1
Severity: normal

Dear Maintainer,

this issue might have security implications, since that's what capabilities
are used for.

See this service file:


ExecStart=/bin/readlink /proc/1/exe

This runs on my machine.

However, if I change the two Capability lines into


Then readlink is denied access to the file. Despite the fact that
neither capability is supposed to do that at all!


