Sensitive mounts

A bind mount punches a hole in the container's filesystem view straight through to the host. Three kinds of mount turn that into a full escape: a host filesystem path gives direct read and write of host files, a runtime control socket gives command of the engine, and host procfs or sysfs paths expose kernel interfaces that run a program on the host. Enumerate what is mounted first, with cat /proc/self/mountinfo or mount.

Subtopics#

  • Host path mount: a host directory, often the whole root filesystem, bound into the container.
  • Runtime socket mount: the engine's control socket (docker.sock, containerd.sock) bound into the container.
  • procfs and sysfs: writable host /proc and /sys paths that hand the kernel a program to run on the host.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more