The issue isn't that the containers have permissions they weren't assigned. It's that the system configuration allows any (host) user to make a container with any permissions, without sudo.
OK, so if you can pass the host root filesystem to a container and then write files or execute code with root privileges on that filesystem, I would definitely consider that a container escape. You're executing arbitrary code on the host from within a container.
11 Comments
traxex@lemmy.dbzer0.com · 68 pts · 2d
Or just delete that racist shitware.
NaibofTabr@infosec.pub · 33 pts · 2d
Once more for the people in the back:
CONTAINERS ARE NOT A SECURITY BARRIER
If you are relying on the container system to isolate and protect the OS from containerized apps, you are wrong.
ColonelThirtyTwo@pawb.social · 21 pts · 2d
FWIW this isn't a container escape. It's just the distro shipping a shitty default that lets the users on the host access root.
NaibofTabr@infosec.pub · 2 pts · 2d
Hmm, maybe I'm misunderstanding. Does "all processes launched in that user session" not include containerized apps?
ColonelThirtyTwo@pawb.social · 6 pts · 1d
The issue isn't that the containers have permissions they weren't assigned. It's that the system configuration allows any (host) user to make a container with any permissions, without sudo.
equivocal@piefed.social · 6 pts · 2d
The issue is that the docker service runs as root and their defaults added the user to a group that allows them to control that service without
sudoSo, the root filesystem can just be passed as a volume to a container and then do whatever you want from there.
NaibofTabr@infosec.pub · -1 pts · 2d
OK, so if you can pass the host root filesystem to a container and then write files or execute code with root privileges on that filesystem, I would definitely consider that a container escape. You're executing arbitrary code on the host from within a container.
mlg@lemmy.world · 3 pts · 2d
I ain't got enuff hardware for qubesos
Go go gadget rootless podman UID mapping and cgroups black magic!
ShutUpWesley@piefed.zip · 29 pts · 2d
What? The "AI first" OS is buggy and insecure? Who could have guessed?
ZombieCyborgFromOuterSpace@piefed.ca · 14 pts · 2d
Omarchy: I'm a fascist, btw.
blarth@thelemmy.club · 10 pts · 2d
Omarchy is a distro for chuds.