3 ms·
The docker daemon runs as a privileged user, so if you're able to break out of the container (which has been shown possible recently) then you can compromise th
by lojack 8y ago
The docker daemon runs as a privileged user, so if you're able to break out of the container (which has been shown possible recently) then you can compromise the entire host OS.
- hjk05 8y agoCould you provide a reference for how to break our?
- lojack 8y agohttps://www.twistlock.com/labs-blog/breaking-docker-via-runc-explaining-cve-2019-5736/ https://www.twistlock.com/labs-blog/breaking-docker-via-runc... This is from a CVE that was released a little over a month ago.
- raesene9 8y agoThat was a runc vuln, which affected other conatinerization solutions on Linux, not just docker. Also it didn't really have anything to do with the Docker daemon running as root, it was triggered by the use of root users in containers (blocked if the user didn't do that, had decent SELinux setups or used user namespaces)