Docker Cgroup Escape

Docker container escape via cgroup release_agent exploit. Use this skill whenever the user mentions container escape, privilege escalation from containers, cgroup exploitation, Docker security testing, or needs to test container breakout vulnerabilities. This skill provides the technique for exploiting the cgroup release_agent mechanism to execute host code from within a container by brute-forcing PIDs through /proc/<pid>/root symlinks.

abelrguezr Updated

File contents

abelrguezr/hacktricks-skills/tree/main/skills/linux-hardening/privilege-escalation/docker-security/docker-breakout-privilege-escalation/release_agent-exploit-relative-paths-to-pids commit 2c938cd3c3

Frequently asked questions

npx skillmds@latest add abelrguezr/docker-cgroup-escape