Several files under /proc and /sys are not data but control knobs: write a path into them and the kernel runs that program later, in the host's context, as root. These are safe only because a normal container does not get a writable host /proc or /sys. When one is bind-mounted in (a surprisingly common misconfiguration) or the container holds CAP_SYS_ADMIN in the initial namespaces, each knob becomes an escape. The catch shared by the executable-handler knobs is that the path must be reachable in the host filesystem namespace, so the helper is dropped on a host-visible path such as the container's overlay upperdir.
Subtopics#
- core_pattern: the program the kernel pipes core dumps to.
- modprobe path: the helper the kernel runs to auto-load a module.
- uevent_helper: the program the kernel runs on a device uevent.
- sysrq-trigger: magic SysRq actions against the host.
- binfmt_misc: registering an interpreter for a file format.
- kcore memory read: reading host kernel memory.
- Host process access: reading host processes through /proc.