logoalt Hacker News

bloppe • yesterday at 6:53 PM • 2 replies • view on HN

CVEs for runc are much more frequent than CVEs for KVM. The attack surface area is bigger, and containers were never intended as a security boundary, but rather as a resource management tool.


Replies

dathinab • yesterday at 11:06 PM

through just from scanning the feature side

> Your files and your account [..]

> Ports and windows on the host

it is quite likely that you can break out even with no linux containers related CVEs. --isolate does seem to fix that somehow but is explicit opt. in and "more painful to use" ... (which creates a UX challenge unlikely to end well from a security POV).

akdev1l • yesterday at 11:48 PM

libkrun exists so we can just run containers inside a virtualized environment without special tooling

➕ show 1 reply