The default seccomp and AppArmor profiles are a large part of what keeps a container contained: they block or restrict syscalls like mount, ptrace, keyctl, unshare, bpf, and perf_event_open. Running with --security-opt seccomp=unconfined or apparmor=unconfined hands those back, which rarely escapes on its own but unlocks the techniques that do.
# Detect the posture
grep Seccomp /proc/self/status # 0 = disabled, 2 = filtered
cat /proc/self/attr/current # AppArmor profile, "unconfined" if off
# With seccomp off, syscalls the default profile blocks now work, e.g. mount and ptrace
unshare -m 2>&1 | head -1
Exploitation notes#
- Unconfined seccomp is the enabler for capability-based escapes that call
mount, forptraceinjection into host processes, and forkeyctlandbpfabuse; combine it with the matching capability. - AppArmor unconfined removes the path and mount restrictions Docker's default profile adds, which is what blocks writing to sensitive
/procpaths in a default container. - Treat a profile that is off as a precondition, then reach for Capability abuse or procfs and sysfs.