A container engine is a privileged service that builds images, pulls them from registries, and starts containers as root. Attacking the engine is distinct from escaping a container: the targets are the control plane it exposes (a daemon API or a control socket, almost always root-equivalent) and the image and registry supply chain behind it. The actual host breakout, once you can start a container, is the same everywhere and lives under Container escape.
Subtopics#
- Docker: the daemon API and the image and registry and build supply chain.
- Podman: the daemonless, rootless-capable engine and its API socket.
- containerd and CRI-O: the low-level OCI runtimes under Docker and Kubernetes.