Runtimes

A container engine is a privileged service that builds images, pulls them from registries, and starts containers as root. Attacking the engine is distinct from escaping a container: the targets are the control plane it exposes (a daemon API or a control socket, almost always root-equivalent) and the image and registry supply chain behind it. The actual host breakout, once you can start a container, is the same everywhere and lives under Container escape.

Subtopics#

  • Docker: the daemon API and the image and registry and build supply chain.
  • Podman: the daemonless, rootless-capable engine and its API socket.
  • containerd and CRI-O: the low-level OCI runtimes under Docker and Kubernetes.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more