Container Escape Vulnerability Research
Escaping containers using the Dirty Pipe vulnerability | Datadog Security Labs

Escaping containers using the Dirty Pipe vulnerability | Datadog Security Labs

3/25/2022 · Eric Mountain, Christophe Tafani-Dereeper, Tommy McCormick, Frederic Baguelin

What this post added

This post presents a proof-of-concept exploit for container escape using the Dirty Pipe vulnerability. It details how the vulnerability can be used to overwrite the runC binary on the host, enabling privilege escalation from within an unprivileged container. The post includes a walkthrough of the exploit, code snippets, and discusses defense mechanisms.

Read the original post ↗