Dirty COW

Dirty COW is a race in the kernel's copy-on-write handling of private memory mappings. It lets an unprivileged process write to pages it should only be able to read, which turns into overwriting read-only files on disk. From a container it escapes by overwriting a host-reachable read-only file, classically a setuid binary or a mapped host file.

bash
# Public PoCs overwrite a chosen read-only file via the madvise/write race.
./dirtycow /host/usr/bin/passwd '<payload>'

Exploitation notes#

  • It needs a reachable host file to overwrite, so it is strongest with a Host path mount or a mapped host binary.
  • The write targets the page cache, so it affects the on-disk file without needing write permission on it.
  • It is an old flaw but still present on long-lived unpatched kernels; confirm the host kernel version before relying on it.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more