Taggart :ifin: on Nostr: I haven't seen a more complete container escape POC for #CopyFail. Is this it? ...
I haven't seen a more complete container escape POC for #CopyFail. Is this it?
Basically, the exploit will be able to write anything in a container that references the same inode as the host, as long as it can get a file descriptor to it. While some files (/etc/resolv.conf) could be candidates without a bind mount/hostPath mount, they would be unhelpful for escape.
As anyone seen other examples?
Published at
2026-05-05 15:15:54 UTCEvent JSON
{
"id": "b8d49e9a4261120e33c2fee9d8985648762fe5929594178c1296d35b722e39e3",
"pubkey": "3ba412ac4b14c4b37cd6ed16b9d262ad4ffefb05c5b6c6b3e15e381471b1221a",
"created_at": 1777994154,
"kind": 1,
"tags": [
[
"t",
"copyfail"
],
[
"proxy",
"https://infosec.exchange/users/mttaggart/statuses/116522624938612983",
"activitypub"
],
[
"client",
"Mostr",
"31990:6be38f8c63df7dbf84db7ec4a6e6fbbd8d19dca3b980efad18585c46f04b26f9:mostr",
"wss://relay.ditto.pub"
]
],
"content": "\n\nI haven't seen a more complete container escape POC for #CopyFail. Is this it? \n\nBasically, the exploit will be able to write anything in a container that references the same inode as the host, as long as it can get a file descriptor to it. While some files (/etc/resolv.conf) could be candidates without a bind mount/hostPath mount, they would be unhelpful for escape.\n\nAs anyone seen other examples?",
"sig": "55ecd5dfdc839bf87ed6297d97b6b5affd28d7b5c984ff2e243a12f38b901b90e4b5bebc7b1a0ce1d470b7b0f41c85054d2e7c6d81aebdb896d55d3f1a1158d1"
}