
Escaping containers using the Dirty Pipe vulnerability | Datadog Security Labs
3/25/2022
This post presents a proof-of-concept exploit for container escape using the Dirty Pipe vulnerability. It details how the vulnerability can be used to overwrite the runC binary on the host, enabling privilege escalation from within an unprivileged container. The post includes a walkthrough of the exploit, code snippets, and discusses defense mechanisms.