Leaky Vessels

Leaky Vessels is a family of runtime breakouts rooted in container startup. A file descriptor to a host directory is left open when the container's process begins, and working-directory handling can be pointed at that descriptor, so a crafted image or build step resolves paths in the host filesystem instead of the container. The result is reading or writing host files and executing code on the host.

dockerfile
# A malicious image sets WORKDIR to a path that resolves through the leaked host fd,
# so the container's process starts with a view of a host directory.
WORKDIR /proc/self/fd/<leaked>/..

Exploitation notes#

  • Variants affect both the running-container path and the image-build path (BuildKit), so a poisoned base image or build step is a delivery route, covered under BuildKit RCE.
  • The escape runs when the container or build starts, needing no privileged flag.
  • Patched runtimes close the descriptor and validate the working directory; unpatched hosts remain exposed through any image they build or run.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more