CAP_SYS_ADMIN

CAP_SYS_ADMIN is the catch-all administrative capability and the one most often added back. It permits mount, cgroup management, and many namespace operations, which is enough to escape on its own. The reliable route is the cgroup release_agent escape, which needs exactly this capability.

bash
# Confirm it is effective
capsh --print | grep -q cap_sys_admin && echo have

# Mount a cgroup hierarchy and arm release_agent (see cgroups-release-agent for the full chain)
mkdir /tmp/cg && mount -t cgroup -o rdma cgroup /tmp/cg

Exploitation notes#

  • The mount right also lets you remount a read-only /proc/sys writable and mount the host block device directly.
  • It is the capability behind most sensitive /proc and /sys writes, so pair it with procfs and sysfs.
  • The full chain is in cgroups release_agent.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more