3 ms·
FYI: I had tried this exploit with rootless podman containers to write to read-only mounts, but the exploit failed. I am not sure if the default container runti
by exceptione 5mo ago
FYI: I had tried this exploit with rootless podman containers to write to read-only mounts, but the exploit failed. I am not sure if the default container runtime in Podman is resistant against these attacks or if it assumes Docker running containers with higher privileges, but at least it was a pleasant observation. (kernel 6.18)
- tptacek 5mo agoAre you not using OverlayFS? The exploit vector here relies on OverlayFS. What you want to reason about generally is (a) whether you have AF_ALG sockets exposed and (b) whether attackers have access to files (via inode) whose cached contents will affect other processes.
- exceptione 5mo agoI had used this exploit. https://github.com/raesene/vuln_pocs/blob/main/CVE-2026-31431/podman/check.sh https://github.com/raesene/vuln_pocs/blob/main/CVE-2026-3143...