logoalt Hacker News

cute_boitoday at 7:03 PM1 replyview on HN

It is security boundary but a weak one. Escaping from docker is very hard.


Replies

rvztoday at 10:58 PM

> Escaping from docker is very hard.

You mean a microVM.

A docker LPE (local privilege escalation) requires a kernel exploit such as Copyfail would work under docker but not in a microVM.