3 ms·
Correct, but it is definitively worth updating for on high-profile systems. I have not tested it, but because I have included the namespace escape in the explo
by Unroll0201 3y ago
Correct, but it is definitively worth updating for on high-profile systems.
I have not tested it, but because I have included the namespace escape in the exploit for KernelCTF, it may be able to break out of LXC containers and privileged Docker containers running on vulnerable Linux kernels.
- dathinab 3y agoif it works for LXC containers shouldn't it also work for unprivileged (but non VM) docker containers?
- Unroll0201 3y agoThis is an educated guess, but I believe unprivileged Docker containers cannot create (user) namespaces. Hence, the vulnerability cannot be triggered, since the exploit requires interaction with nf_tables, which requires (namespace) root. LXC containers and privileged Docker containers allow these namespaces to be made inside of them, whilst unprivileged Docker containers do not.