8 ms·
Forgot to include "LPE" (local...) in the title so most of us can get back to weekending.
by password4321 2mo ago
Forgot to include "LPE" (local...) in the title so most of us can get back to weekending.
- circularfoyers 2mo agoSince this enables container escape, sounds like this might still impact quite a lot of us?
- hollerith 2mo agoA lot of us rely on Linux containers' being escape-proof? I would have hoped that only a few of us are so misinformed as to do that.
- password4321 2mo agoI guess, if you thought Docker/etc. was a security boundary
- markasoftware 2mo agoRunpod, digital ocean's gpu cloud, and at least a few others use Linux containers for isolation between tenants (look at Wiz's blog post about the nvidia container toolkit bug; digitalocean just puts everyone in a massive k8s cluster)
- stingraycharles 2mo agoWhy aren’t they using a fast VM like Firecracker?
- himata4113 2mo agoTo squeeze out 5% more profit.
- circularfoyers 2mo agoI know there's a lot you can do in k8s to mitigate it, but I didn't think that prevented it outright.
- insanitybit 2mo agoThey are a security boundary. The fact that you need a vulnerability to escape them is proof of that. They just don't have a particularly high cost of escape because reachable kernel vulnerabilities are so common.
- worthless-trash 2mo agoSome people clearly do use containers as deployment mechanism, with security not in mind.
- zbentley 2mo agos/some/most/ That's not meant to be snide, just true, I think.
- CodesInChaos 2mo agoI never understood why kubernetes doesn't use a VM-per-pod model by default.
- dijit 2mo agoEscape from docker containers is trivially easy, if you are able to run as the root user in the container itself. Many (maybe most) containers actually default to running programs as root. Kernel exploit not required.
- maple3142 2mo agoIf you are given a shell with `docker run -it --rm alpine:3 sh`, can you read the /etc/shadow on the host without kernel exploit? Assuming the docker and kernel are sufficiently update-to-date (e.g. latest Docker on Debian Stable).
- chlorion 2mo agoNo. The "root" you get in docker is not actually root outside of the namespace the container in running in. Assuming no bugs in the kernel, it should not be able to do anything more than the UID that it's mapped from.
- XorNot 2mo agoThere was a virtual machine KVM escape found like 2 weeks ago. Nothing is a security boundary anymore.
- ActorNightly 2mo agoIf you run critical containers under Linux instead of a dedicated hypervisor, you deserve to get hacked.
- Chu4eeno 2mo agothey also found a type confusion in firefox/ionmonkey, so you can go from random website to pwned very quickly.
- jurf 2mo agoGot me confused for a sec, as the exploit in the top comment implies JavaScript→root, but it actually relies on two separate exploits.
- phire 2mo agoNot really. Generally we use "Local Privilege Exploit" to describe an exploit that goes from a reasonably normal user privileges to root privileges. And we don't usually worry about them, because an application with normal user privileges can already to so much damage. But this exploit can be triggered from inside a tightly sandboxed process, such as firefox's isolated browser process. Which means the attacker now only needs to chain two exploits together: One javascript exploit to get local code execution in an isolated sandbox, and this one to jump all the rest of the way to kernel mode. Which means, you should update both firefox, and your linux kernel.
- franga2000 2mo agoRealistically, if you have a browser sandbox, the system LPE exploit gives you very little more. Everything interesting on a desktop system is accessible by the user account directly.
- mjg59 2mo agoThis gets you code execution in the kernel, at which point sandboxing is irrelevant.
- password4321 2mo ago> this exploit can be triggered from inside a tightly sandboxed process Thank you for emphasizing this important detail. > you should update both firefox, and your linux kernel No doubt, update all the things! My point was, it can most likely wait until Monday.
- iririririr 2mo agoas if in these times there aren't hundreds of "0days" in everyone's hands waiting to be burned for situations just like this. from ssh to node, so much stuff showing every other week. might as well call everything remote unless you run 100% behind wireguard or something.
- pixl97 2mo agoPretty much, the rate at which quality exploits are dropping is mind blowing.