|
|
|
|
|
by longtermsec
2585 days ago
|
|
The idea that it's trivial to break out of any Docker style container just doesn't reflect reality. -- not just being contrarian here, actually, the reality is that it might be trivial. and it was demonstratively trivial for a long time (see CVE-2019-5736) As for contained.af -- its not a good indicator, it mostly indicates that the reward doesnt meet the market price for demonstrating an escape from a set of hardened namespaces (which is going to cost more than an escape from "any docker container"). |
|
Also not specifically a Docker vulnerability, it was a runc issue which also affected other Linux containerization software (e.g. lxc)
But despite all that, that's just an example of what I was talking about, all software has vulns, including runc, including gvisor.
Stating that "containers don't contain" implies that it's not just a specific bug, but that architecturally the process is flawed (at least IMHO), which I would suggest is at the least an over-simplification.
as to contained.af, well if it was indeed "trivial" then surely not a large reward would be required :)