The most common container escapes need no exploit at all: the container was simply configured with more power than isolation can survive. Each setting here removes one of the walls, and several of them collapse straight to host code execution. Check what you were given first:
capsh --print 2>/dev/null # capabilities in the container
cat /proc/self/status | grep -i cap # CapEff bitmask
cat /sys/fs/cgroup/*/release_agent 2>/dev/null
Subtopics#
- Privileged flag: the all-in-one
--privileged, which grants everything below at once. - Capability abuse: a single dangerous capability, each with its own route to the host.
- Device access: raw host devices exposed in the container.
- Unconfined seccomp or AppArmor: a weakened or disabled syscall and LSM profile.
- cgroups release_agent: a writable release_agent that runs a program on the host.