Hacker News new | ask | show | jobs
by t0mas88 34 days ago
It could work for container escape?
1 comments

Containers, even with root user, are often stripped of these capabilities unless --privileged
However, some privs can be gained in namespaces/unshare.