CAP_SYS_ADMIN is the catch-all administrative capability and the one most often added back. It permits mount, cgroup management, and many namespace operations, which is enough to escape on its own. The reliable route is the cgroup release_agent escape, which needs exactly this capability.
# Confirm it is effective
capsh --print | grep -q cap_sys_admin && echo have
# Mount a cgroup hierarchy and arm release_agent (see cgroups-release-agent for the full chain)
mkdir /tmp/cg && mount -t cgroup -o rdma cgroup /tmp/cg
Exploitation notes#
- The
mountright also lets you remount a read-only/proc/syswritable and mount the host block device directly. - It is the capability behind most sensitive
/procand/syswrites, so pair it with procfs and sysfs. - The full chain is in cgroups release_agent.