Skip to content
Threat Feed

Tag

Container-Escape

14 briefs RSS
high advisory

Chroot Execution in Container Context on Linux

An Elastic detection rule targets `chroot` execution on Linux systems in a containerized context, often indicative of container breakout attempts to achieve privilege escalation by pivoting to an alternate root filesystem, typically leveraging sensitive host mounts.

runc +1 container-escape privilege-escalation linux elastic
1r 1t
high advisory

Nsenter to PID Namespace for Privilege Escalation on Linux

Elastic has released a detection rule to identify the use of the `nsenter` utility targeting a Process ID (PID) with specific namespace flags on Linux systems, a technique commonly employed by attackers to escape container environments or escalate privileges by gaining host context.

privilege-escalation container-escape linux endpoint auditd
1r 1t
medium advisory

Linux Container Escape via Kernel core_pattern Modification

Attackers can exploit a Linux kernel vulnerability allowing a process inside a container to modify the `/proc/sys/kernel/core_pattern` file, enabling the execution of arbitrary code as root on the host system upon a core-dump, thereby achieving a full container-to-host escape and privilege escalation.

Linux kernel container-escape privilege-escalation linux kubernetes endpoint
1r 1t
critical advisory

Incus Container Escape via Arbitrary File Read/Write (CVE-2026-48749)

A critical vulnerability, CVE-2026-48749, in Incus allows an attacker to achieve arbitrary file read and write on the host filesystem with root privileges by crafting a malicious container image containing a symlink, bypassing validation, and potentially leading to arbitrary command execution.

incus container-escape privilege-escalation vulnerability-exploitation linux
1t
critical advisory

Incus Argument Injection Vulnerability Leads to Arbitrary File Write and Command Execution

An argument injection vulnerability (CVE-2026-48755) exists in Incus due to improper validation of the user-provided backup compression algorithm, allowing an authenticated attacker to inject arbitrary arguments into the command line, leading to an arbitrary file write on the host and subsequent arbitrary command execution.

Incus argument-injection arbitrary-file-write remote-code-execution container-escape linux
2r 5t 2i
high advisory

Kata Containers Guest-to-Host Root Escape via Virtiofs FUSE_SYMLINK

A vulnerability in Kata Containers allows a guest root user to escalate privileges to host root by exploiting the virtiofs shared file system to create arbitrary symlinks on the host.

kata-containers/kata-containers kata-containers virtiofs fuse privilege-escalation container-escape
2r 1t
critical advisory

KubeVirt virt-handler Symlink Vulnerability Leading to Container Escape (CVE-2026-7374)

CVE-2026-7374 allows an authenticated OpenShift user with edit permissions in a single namespace to escalate privileges to full cluster control by exploiting improper symlink validation in KubeVirt's virt-handler component when connecting to VM console sockets.

virt-handler +1 kubeVirt openshift symlink container escape privilege escalation
2r 1t 1c
high advisory

NanoClaw Host/Container Filesystem Boundary Vulnerability

NanoClaw is vulnerable to a host/container filesystem boundary vulnerability in outbound attachment handling and outbox cleanup, potentially allowing a compromised container to read arbitrary host files or cause recursive deletion of paths outside the intended cleanup target.

NanoClaw filesystem boundary vulnerability container escape privilege escalation
2r 2t 1c
high advisory

Potential Chroot Container Escape via Mount

The rule detects a potential chroot container escape via mount, which involves a user within a container mounting the host's root file system and using chroot to escape the containerized environment, indicating a privilege escalation attempt.

Elastic Defend +2 container-escape privilege-escalation linux
2r
high advisory

Chroot Execution in Container Context on Linux

Detects suspicious chroot execution within a Linux container context, potentially indicating a container escape attempt by pivoting to an alternate root filesystem.

Elastic Defend +1 container-escape privilege-escalation linux chroot
2r 1t
critical advisory

LXD Backup Import Bypass Allows Privilege Escalation in Restricted Projects

A vulnerability in LXD allows an attacker with instance-creation rights in a restricted project to bypass project restrictions and escalate privileges by crafting a malicious backup archive.

lxd privilege-escalation container-escape cve-2026-34178
2r 1t
high advisory

Kata Containers CopyFile Policy Subversion via Symlinks

An oversight in the CopyFile policy in Kata Containers allows untrusted hosts to write to arbitrary locations inside the guest workload image via symlinks, enabling binary overwrites and data exfiltration.

kata-containers/kata-containers kata-containers container-escape symlink
3r 2t 1c
medium advisory

Suspicious Unshare Usage for Namespace Manipulation

The `unshare` command is used to create new namespaces in Linux, which can be exploited to break out of containers or elevate privileges by creating namespaces that bypass security controls.

Elastic Defend +6 privilege-escalation container-escape linux
2r 2t 1c updated
medium advisory

Suspicious Unshare Usage for Container Escape and Privilege Escalation

The rule identifies suspicious usage of unshare to manipulate system namespaces, which can be utilized to escalate privileges or escape container security boundaries.

Elastic Defend for Containers privilege-escalation container-escape linux
2r 2t