The runtime that starts a container briefly straddles the container and host boundaries, and its shim keeps a control channel open afterward. Both have produced reliable, widely weaponized breakouts.
Subtopics#
- runc /proc/self/exe overwrite: overwrite the host runtime binary as it enters the container.
- Leaky Vessels: a leaked file descriptor and working-directory confusion at startup.
- containerd-shim API: reach the shim's control socket from a container.
- CRI-O cr8escape: inject kernel parameters through the runtime's sysctl handling.