Sandboxed runtime escapes

Sandboxed runtimes change the escape problem. Instead of sharing the host kernel directly, they put something in between: gVisor runs a userspace kernel that emulates syscalls, and Kata and other microVM runtimes run each workload in a lightweight virtual machine. A classic container escape does not apply; the target is a flaw in the sandbox's own interface back to the host.

Subtopics#

  • gVisor: escaping the userspace kernel and its host interface.
  • Kata Containers: escaping the guest VM to the host.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more