가입 후 초대 링크를 공유하면 동영상 재생 및 초대 보상을 받을 수 있습니다.

Oren Yomtov
@orenyomtov
security researcher; RSAC, Black Hat, and DEF CON (2 times) speaker
가입 May 2009
2.5K 팔로잉 중    5.2K 팬
We escaped Docker's hypervisor with three lines of bash. CVE-2026-77179: A container gets complete read and write access to the host filesystem. When you mount a folder into a container, Docker's VMM uses virtio-fs, and the file server runs on the host. Because of a TOCTOU bug, if a container opens a file, deletes it while holding its file handle open, and replaces the parent folder with a symlink, the kernel will follow the symlink to anywhere on the host. Full technical breakdown:
더 보기
0
25
1.3K
156
커뮤니티로 전달