Guest to host escape

Proxmox runs two kinds of guest. VMs are QEMU/KVM, so escaping one is a QEMU device-model escape that lands in the QEMU process on the node. Containers are LXC, so escaping one uses the standard Linux container-escape primitives (privileged config, dangerous mounts, host namespaces). Either outcome is code execution on the Debian node, from which the cluster is reachable.

text
Proxmox guest escape surfaces:
- VMs: the QEMU device models (virtio, NICs, USB, SCSI) -> see KVM/QEMU
- LXC: privileged containers, bind mounts, shared namespaces -> see Container escape

Exploitation notes#

  • For VMs, the technique and surface are identical to KVM and QEMU guest to host escape, bounded by the node's QEMU confinement.
  • For LXC, especially privileged containers, the breakout is the generic Container escape, and it lands directly on the node.
  • Once on the node, /etc/pve and the cluster communication give lateral movement to other nodes; see Management plane.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more