Docker and Kubernetes drop most capabilities by default, but workloads routinely add one or two back for convenience, and each dangerous capability is its own escape. Read the effective set, then pick the matching technique.
capsh --print | sed -n 's/^Current: //p'
grep CapEff /proc/self/status # decode with: capsh --decode=<hex>
Subtopics#
- CAP_SYS_ADMIN: mount, cgroups, and namespace operations.
- CAP_SYS_PTRACE: inject into host processes.
- CAP_SYS_MODULE: load a kernel module.
- CAP_DAC_READ_SEARCH: read any host file.
- CAP_DAC_OVERRIDE: write host files past permissions.
- CAP_SYS_RAWIO: raw I/O and physical memory.
- CAP_NET_RAW: craft and sniff raw packets.
- CAP_BPF: load eBPF programs.