CAP_SYS_RAWIO

CAP_SYS_RAWIO permits raw I/O: iopl/ioperm port access and reads and writes of physical memory devices like /dev/mem and /dev/port when they are present. That is a direct window into kernel memory, which can be read for secrets and KASLR, or written to patch kernel structures.

bash
capsh --print | grep -q cap_sys_rawio && echo have
ls -l /dev/mem /dev/port 2>/dev/null
# Read physical memory for kernel structures / secrets
dd if=/dev/mem bs=1M count=16 2>/dev/null | strings | head

Exploitation notes#

  • The capability is only as useful as the exposed devices: a privileged container has /dev/mem; otherwise it must be granted with --device.
  • Writing /dev/mem to patch the kernel (for example disabling a credential check) is powerful but fragile across kernel versions; reads for a kernel exploit are more portable.
  • Related device routes are under Kernel memory devices.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more