4 ms·
Since this enables container escape, sounds like this might still impact quite a lot of us?
by circularfoyers 3mo ago
Since this enables container escape, sounds like this might still impact quite a lot of us?
- hollerith 3mo agoA lot of us rely on Linux containers' being escape-proof? I would have hoped that only a few of us are so misinformed as to do that.
- password4321 3mo agoI guess, if you thought Docker/etc. was a security boundary
- markasoftware 3mo agoRunpod, digital ocean's gpu cloud, and at least a few others use Linux containers for isolation between tenants (look at Wiz's blog post about the nvidia container toolkit bug; digitalocean just puts everyone in a massive k8s cluster)
- stingraycharles 3mo agoWhy aren’t they using a fast VM like Firecracker?
- himata4113 3mo agoTo squeeze out 5% more profit.
- circularfoyers 3mo agoI know there's a lot you can do in k8s to mitigate it, but I didn't think that prevented it outright.
- insanitybit 3mo agoThey are a security boundary. The fact that you need a vulnerability to escape them is proof of that. They just don't have a particularly high cost of escape because reachable kernel vulnerabilities are so common.
- worthless-trash 3mo agoSome people clearly do use containers as deployment mechanism, with security not in mind.
- zbentley 3mo agos/some/most/ That's not meant to be snide, just true, I think.
- CodesInChaos 2mo agoI never understood why kubernetes doesn't use a VM-per-pod model by default.
- dijit 3mo agoEscape from docker containers is trivially easy, if you are able to run as the root user in the container itself. Many (maybe most) containers actually default to running programs as root. Kernel exploit not required.
- maple3142 3mo agoIf you are given a shell with `docker run -it --rm alpine:3 sh`, can you read the /etc/shadow on the host without kernel exploit? Assuming the docker and kernel are sufficiently update-to-date (e.g. latest Docker on Debian Stable).
- chlorion 3mo agoNo. The "root" you get in docker is not actually root outside of the namespace the container in running in. Assuming no bugs in the kernel, it should not be able to do anything more than the UID that it's mapped from.
- XorNot 3mo agoThere was a virtual machine KVM escape found like 2 weeks ago. Nothing is a security boundary anymore.
- ActorNightly 3mo agoIf you run critical containers under Linux instead of a dedicated hypervisor, you deserve to get hacked.