Article 4AG9N [$] A container-confinement breakout

[$] A container-confinement breakout

by
jake
from LWN.net on (#4AG9N)

The recently announcedcontainer-confinement breakout for containers started with runc is interesting froma few different perspectives.For one, it affects more than just runc-based containers as privileged LXC-based containers (and likelyothers) are alsoaffected, though the LXC-based variety are harder to compromise than therunc ones.But it also, once again, shows that privilegedcontainers are difficult-perhaps impossible-to create in a secure manner.Beyond that, itexploits some Linux kernel interfaces in novel ways and the fixes use aperhaps lesser-known system call that was added to Linux less than fiveyears back.

External Content
Source RSS or Atom Feed
Feed Location http://lwn.net/headlines/rss
Feed Title LWN.net
Feed Link https://lwn.net/
Reply 0 comments