mirror of
https://github.com/jackyzha0/quartz.git
synced 2025-12-26 06:14:06 -06:00
375 B
375 B
Every pod (and therefore container) can do direct syscalls to the kernel of the node.
If there are security bugs in the kernel, these can be exploited by the containers directly.
Links:
from:: CKS Video Course
contributes to:: Container Isolation related research:: What Have Namespaces Done for You Lately?
202403241148