A Guide to Container Privilege Escalation Vulnerabilities
ID: da770a56-c6e7-5673-a3e9-91d42941b7be
STIX ID: report--da770a56-c6e7-5673-a3e9-91d42941b7be
Feed Name: Aikido Security's Blog
Threat Score
This guide reviews container privilege escalation risks, highlights recent critical CVEs that enable container-to-host escapes (runC and kernel/OverlayFS issues), and gives practical mitigation steps for Docker and Kubernetes — including no-new-privileges, dropping capabilities, read-only filesystems, user namespace remapping, securityContext settings, admission policies (e.g., Kyverno), and image/config scanning and runtime monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
