containerd-shim API

Each container's containerd-shim listens on a control socket in the abstract Unix socket namespace. Abstract sockets are keyed by the network namespace, so a container that shares the host network namespace can reach a shim's API and ask it to start a process, which runs on the host with the shim's privileges.

bash
# Requires the host network namespace (abstract sockets are per-netns)
cat /proc/net/unix | grep -a containerd-shim        # locate the abstract socket
# Speak the shim's ttRPC API to create/exec a process on the host

Exploitation notes#

  • The precondition is the shared host network namespace; see Host network namespace.
  • The shim runs outside the container, so a process it starts is a host process.
  • Patched containerd moves the socket out of reach and checks the caller; the technique targets unpatched hosts with host-networked containers.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more