3 ms·
They're using 'contain' to mean 'keep isolated'. If you put some malware in a docker container, you can't rely on docker to keep the rest of your system safe.
by OscarCunningham 3y ago
They're using 'contain' to mean 'keep isolated'. If you put some malware in a docker container, you can't rely on docker to keep the rest of your system safe.
- FpUser 3y agoDoes the fact that docker runs as a root have something to do with it?
- progval 3y agoYes, but even rootless containers rely on user namespaces, which are a recurring source of privilege escalation vulnerabilities in Linux.
- insanitybit 3y agoThe issue of root vs rootless is unrelated to escaping the container. User namespaces lead to privescs because attackers who can enter a namespace and become the root within that namespace have access to kernel functionality that is far less hardened (because upstream has never considered root->kernel to be a privesc and, of course, most people focus on unprivileged user -> kernel privesc). The daemon running as root doesn't change anything there
- insanitybit 3y agoNo, it's because the malware would have direct access to the (privileged) Linux Kernel via system calls.
- scoot 3y agoGot it, thanks.