/dev/mem and /dev/kmem expose physical and kernel virtual memory. Where they are present in the container (privileged, or granted) and readable, they allow dumping kernel memory for secrets and addresses; where writable, they allow patching the live kernel.
ls -l /dev/mem 2>/dev/null
dd if=/dev/mem bs=1M count=32 2>/dev/null | strings -n 12 | grep -i 'key\|token' | head
Exploitation notes#
- Modern kernels restrict
/dev/memto the first megabyte unlessCONFIG_STRICT_DEVMEMis off, so broad reads need a permissive host configuration orCAP_SYS_RAWIO. - Reading for KASLR and secrets is portable; writing kernel structures (for example a credential check) is version-specific and risky.
- This pairs with CAP_SYS_RAWIO.