4 ms·
Yes, it is trivial for a root user in an LXC container to break out. One can load a kernel module from within a container, for example. LXC containers do not pr
by throwaway092834 13y ago
Yes, it is trivial for a root user in an LXC container to break out. One can load a kernel module from within a container, for example. LXC containers do not provide security partitioning at all.
- shykes 13y agoThis is just totally wrong. Any decent container configuration (including the default docker configuration) will agressively drop capabilities, preventing you from doing this, and any other script-kiddie attack. See my other comment in this thread for a more accurate answer.
- throwaway092834 13y agoNot wrong at all. He asked about LXC. Privilege restrictions are not part of LXC.
- justincormack 13y agoYes, you probably need a proper kernel vulnerability, which you can exploit in a reduced environment. Not trivial, but not impossible, scanning this years CVEs some would probably be sufficient (eg ones that only nees socket access).
- riquito 13y agoCan't you take advantage of a kernel vulnerability on any reduced environment, regardless of LXC?
- throwaway092834 13y agoNot in certain container types such as a full VM.