logoalt Hacker News

Havoctoday at 10:05 AM1 replyview on HN

Unprivileged LXCs get pretty close. Less unified design wise but on some aspects better - kernel escape doesn’t land you on a 0 UID


Replies

zenopraxtoday at 12:38 PM

> "kernel escape doesn’t land you on a 0 UID"

I'm not sure I agree/understand. If you've somehow bypassed AppArmor and cgroup mechanisms then any UID/GID remapping is irrelevant. At this point you're in a position to directly manage memory.

What do you mean by "kernel escape"?

show 2 replies