Skip to content

Topic

Sandbox Escape

A security exploit technique in which code breaks out of an isolated execution environment to gain unauthorized access to the host system or process.

Current stories

security1 publisher

A guest escape can reach Firecracker's blocked syscalls through io_uring

Amazon patched a symlink-following chown in Firecracker's jailer that only affected aarch64. Behind it sits a seccomp policy that permits io_uring, and researcher antitree shows how that hands back file-system calls the filter denies.

Publishers:antitree.com

Reality

Evidence58
Adoption30
Hype gap−15
Incentives32
Confidence50