When the runtime joins a container to run a process, it is reachable through /proc/self/exe from inside that container for a brief window. A malicious image or a process that the operator execs into can open that path and overwrite the host runtime binary. The next time the runtime runs, it executes attacker code on the host as root.
# The malicious container ships an entrypoint that races /proc/self/exe of the runtime,
# reopens it O_WRONLY once the handle is available, and writes a #!/proc/self/exe payload.
# Weaponized public PoCs exist; the trigger is any subsequent `run` or `exec`.
Exploitation notes#
- It fires on the operator's action: either starting the malicious image or
execing into a container the attacker controls. - The write replaces a host-wide binary, so every later container start runs the payload until the runtime is restored.
- Patched runtimes make the binary read-only during entry; the technique is historical but still found on unpatched hosts.