Rootless Podman runs the whole stack as an ordinary user, using a user namespace where container UID 0 maps to the invoking user and a range of subuid/subgid values. For an attacker this reframes the escape: breaking out lands you as that unprivileged host user, not root, so the goal shifts to what that user can reach and to local privilege escalation from there.
cat /proc/self/uid_map # 0 <hostuid> 1 then the subuid range
cat /etc/subuid /etc/subgid # the mapped ranges for the user
podman unshare cat /proc/self/uid_map # view inside the podman user namespace
Exploitation notes#
- Capability-based escapes still work inside the namespace but apply only to resources the mapped user owns, so they do not reach host root directly.
- The realistic path is escape to the host user, then ordinary Linux local privilege escalation; treat the rootless container as a foothold as that user.
- A rootful Podman (run as root or via the system socket) does not have this limit; confirm the mapping before assuming confinement.