在 Linux 平台上启用了 CUSE(Character Device in Userspace)功能的 Google gVisor 中,主机文件辅助程序(gofer)存在对资源到错误域的不当暴露问题(漏洞发生在 commit 573a9e73cf844f 之前)。本地攻击者若具备容器镜像部署权限,可利用此漏洞在主机系统上实现以 root 权限执行代码。具体而言,攻击者通过在容器镜像中包含一个 /dev/cuse 字符设备节点,使设备打开操作穿透至主机,从而允许被沙箱隔离的攻击者注册主机设备,并利用 CUSE 无
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet