Kai Ole Hartwig

name of the term: Container Escape
descriptions of the term:

Definition

Definition. The process by which an attacker breaks out of a running container and gains access to the host kernel, the host filesystem or neighboring containers. Typical causes: kernel vulnerabilities, excessive container capabilities, wrongly mounted sockets (docker.sock), privileged containers, missing user namespaces.

Why it matters. Container isolation is not as absolute as many architecture diagrams suggest. On Linux it is based on namespaces, cgroups and seccomp/AppArmor, and each of these layers has had CVEs in recent years. Pod Security Standards and kernel patching address exactly this.

Related. Pod Security Standards, Kernel LPE, Kernel Hardening, Runtime Security

Type of term: definition
Language of the term (2 char ISO code): en
Back