gVisor interposes a userspace kernel, the Sentry, between the container and the host. The container's syscalls hit the Sentry, not the host kernel, so most container escapes and kernel exploits simply do not reach the host. An escape instead needs a bug in the Sentry's own syscall emulation or in the restricted host surface (the Gofer and the small set of host syscalls the Sentry itself makes).
# Confirm the sandbox: gVisor reports a distinctive kernel identity
uname -a # gVisor-specific version string
dmesg 2>/dev/null | head
Exploitation notes#
- The host kernel surface is deliberately tiny, so the realistic targets are logic flaws in Sentry syscall handling or the file-proxy (Gofer) interface.
- Standard primitives like a privileged flag or a mounted socket do not translate: there is no host kernel behind the syscall to abuse.
- Fingerprint gVisor early, because it changes which techniques are even applicable.