4 ms·
This is very interesting, because most docker break outs I see are exploits in the linux kernel, but this is one of the few in the containerization components t
by yutghgh 8y ago
This is very interesting, because most docker break outs I see are exploits in the linux kernel, but this is one of the few in the containerization components themselves (first one I remember in runC).
- cpuguy83 8y agoDefinitely not the first. There was one with leaking file descriptors which weren't opened with O_CLOEXEC. Another with ptrace (fixed by making the process non-dumpable).