3 ms·
You should still be rather careful with this, as they have access to the same kernel as the host, and could potentially jailbreak through kernel vulnerabilities
by rrttt 9y ago
You should still be rather careful with this, as they have access to the same kernel as the host, and could potentially jailbreak through kernel vulnerabilities.
- X86BSD 9y agoI have enough confidence in FreeBSD jails to not worry about that. If I found someone who could actually break out of a jail I would at the least buy them dinner anywhere, their choice. You can't modify a running kernel by direct access. And you can't load modules. So it would be a very interesting hack to see.
- rrttt 9y agoIt's been done before, for example the "BadIRET" vulnerability (CVE-2015-5675) was used to jailbreak FreeBSD on the PS4 a couple of years ago.
- X86BSD 9y agoActually it hasn't been done before. That CVE required elevated privelages on the host already. They didn't break out of a jail.
- rrttt 9y agoThey did break out of a jail, the vulnerability was used to gain arbitrary code execution in kernel mode, which was used to modify the cr_prison structure, thus performing a jailbreak.
- X86BSD 9y agoAgain, they already had elevated or root privs. If you've already got root privs nothing will save you.
- rrttt 9y agoThey had root inside a jail, which isn't the same as being root outside the jail. To be able to gain arbitrary code execution in kernel mode from a jail is a security vulnerability.