注册并分享邀请链接,可获得视频播放与邀请奖励。

Oren Yomtov
@orenyomtov
security researcher; RSAC, Black Hat, and DEF CON (2 times) speaker
加入 May 2009
2.5K 正在关注    5.2K 粉丝
We escaped Docker's hypervisor with three lines of bash. CVE-2026-77179: A container gets complete read and write access to the host filesystem. When you mount a folder into a container, Docker's VMM uses virtio-fs, and the file server runs on the host. Because of a TOCTOU bug, if a container opens a file, deletes it while holding its file handle open, and replaces the parent folder with a symlink, the kernel will follow the symlink to anywhere on the host. Full technical breakdown:
显示更多
0
25
1.3K
156
转发到社区