Kernel exploits

Every container shares the host kernel, so a kernel local privilege escalation reachable from the container is a host escape. The reachable surface depends on the seccomp profile and the capabilities granted, which is why an unconfined or user-namespace-enabled container has far more kernel attack surface.

Subtopics#

  • Dirty COW: a copy-on-write race to write read-only files.
  • Dirty Pipe: a pipe page-cache flaw to overwrite read-only files.
  • nf_tables: netfilter bugs reachable through a user namespace.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more