Mar 26, 2026, 11:03 AM
buying escape exploits for containerd and gvisor runtime.
conditions escape should work:
- container is non-root and unprivileged
- default apparmor and secomp policies enforced
- containers using cgroupv2
- containers running on read-only (optional, hard but good to have)
conditions escape should work:
- container is non-root and unprivileged
- default apparmor and secomp policies enforced
- containers using cgroupv2
- containers running on read-only (optional, hard but good to have)
