Device access

A container that can reach host devices escapes through them. A privileged container sees every device; a specific --device grant or CAP_MKNOD exposes one. The two that matter most are the host's root block device (mount it, own the filesystem) and kernel or physical memory (patch the running kernel).

bash
ls -l /dev                      # what devices are visible
cat /proc/partitions            # host block devices, e.g. sda

Subtopics#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more