Remix.run Logo
▲ bloppe 8 hours ago

CVEs for runc are much more frequent than CVEs for KVM. The attack surface area is bigger, and containers were never intended as a security boundary, but rather as a resource management tool.

▲dathinab 4 hours ago | parent | next [-]

through just from scanning the feature side

> Your files and your account [..]

> Ports and windows on the host

it is quite likely that you can break out even with no linux containers related CVEs. --isolate does seem to fix that somehow but is explicit opt. in and "more painful to use" ... (which creates a UX challenge unlikely to end well from a security POV).

▲akdev1l 3 hours ago | parent | prev [-]

libkrun exists so we can just run containers inside a virtualized environment without special tooling

▲zenoprax an hour ago | parent [-]

I was just testing this and it's not clear that it works out of the box. `krun` shows a different kernel than with `crun` but it doesn't reflect the dropped capabilities in the same way. I'm probably holding it wrong but I'm not sure what to look for at the moment.