# Container and Virtualization Escape Vulnerabilities in the Exploitarium Repository

> Explore container and virtualization escape vulnerabilities in the bikini/exploitarium repo, including Docker cp race condition, Gitea act_runner bypass, and QEMU CXL exploit.

- Repository: [bikini/exploitarium](https://github.com/bikini/exploitarium)
- Tags: deep-dive
- Published: 2026-09-06

---

**The Exploitarium repository archives three container and virtualization escape vulnerabilities: a Docker `cp` race condition, a Gitea act_runner namespace bypass, and a QEMU CXL Type-3 mailbox exploit.**

The **bikini/exploitarium** repository is a curated collection of proof-of-concept (PoC) exploits that demonstrate how container and virtualization isolation can be broken through trusted-host interaction failures. Each PoC targets a specific architectural flaw where untrusted code inside a container or VM manipulates host-side resources to achieve escape. This article examines all three archived **container and virtualization escape vulnerabilities** with technical implementation details from the source code.

---

## Docker `cp` Copy-Out Destination Escape (Race Condition)

The Docker `cp` escape exploits a **time-of-check to time-of-use (TOCTOU)** race in the container-to-host file copy mechanism.

### How the Vulnerability Works

In [`docker-cp-copyout-destination-escape/README.md`](https://github.com/bikini/exploitarium/blob/main/docker-cp-copyout-destination-escape/README.md), the vulnerability is described as a race between three operations:

1. The Docker CLI resolves the host destination path and walks the container filesystem
2. The daemon streams the container's contents via `CopyFromContainer`
3. The CLI extracts the tar archive locally using `archive.CopyTo`

The extraction code performs a prefix check with `strings.HasPrefix` to verify that extracted files stay within the destination directory. However, this check can be bypassed when a malicious container replaces a directory with a symlink **after** the path walk observes it but **before** the tar entry is processed.

```bash

# Run the PoC (requires Docker)

chmod +x poc.sh
HOST_BASE=/tmp/docker-cp-copyout-repro ./poc.sh

```

The PoC creates a container where `/tmp/src` is being copied. During the copy operation, the container replaces a subdirectory with a symlink pointing to `../dst2`, causing the host-side extraction to write the marker file outside the intended destination:

```

success=yes
requested_destination=/tmp/docker-cp-copyout-repro/dst
outside_marker_path=/tmp/docker-cp-copyout-repro/dst2/marker
outside_marker_value=container-controlled-host-marker

```

### Root Cause

The `strings.HasPrefix` validation in the extraction logic fails to account for path traversal through symlinks created mid-operation. The raw prefix check treats the resolved symlink target as valid because it technically shares the destination prefix, even when it escapes the intended bounds.

---

## Gitea act_runner `container.options` Host-Namespace Escape

This vulnerability demonstrates how **configuration injection** can bypass container isolation even when `Privileged` mode is explicitly disabled.

### The Attack Vector

The Gitea `act_runner` parses workflow-defined `container.options` and merges them into Docker run configurations via `mergeContainerConfigs()`. According to [`gitea-act-runner-container-options-poc/README.md`](https://github.com/bikini/exploitarium/blob/main/gitea-act-runner-container-options-poc/README.md), the runner preserves dangerous fields without adequate sanitization:

- `PidMode=host` — shares the host PID namespace
- `IpcMode=host` — shares the host IPC namespace
- `CapAdd=ALL` — grants all Linux capabilities
- `SecurityOpt=unconfined` — disables security profiles

```python
python3 poc.py --runner ./act_runner --image ubuntu:22.04

```

The PoC constructs a workflow that requests these options while keeping `Privileged: false`, which the runner accepts. Inside the job container, the exploit uses `nsenter` to enter the host namespaces and create a marker file:

```

[+] verified host marker:
uid=0(root) gid=0(root) groups=0(root)
gitea-act-runner-container-options-poc-ok

```

### Why Privileged=False Doesn't Protect

The runner's threat model assumes that `Privileged: false` provides isolation, but the `container.options` merge logic allows equivalent privilege escalation through individual capability grants and namespace sharing. As implemented in `bikini/exploitarium`, the PoC proves that namespace isolation can be dismantled option-by-option without triggering the privileged container warning.

---

## QEMU CXL Type-3 Mailbox Escape (Virtualization Layer)

The third archived vulnerability targets **hardware emulation code** running at host privilege level, demonstrating that virtualization escapes need not rely on traditional hypervisor bugs.

### CXL Mailbox Mechanism Exploitation

Compute Express Link (CXL) Type-3 devices expose a mailbox interface for configuration and management. In QEMU, this mailbox handling runs with full host privileges. The PoC in `qemu-cxl-type3-mailbox-escape-poc/` crafts mailbox interactions that cause arbitrary code execution:

```bash

# The PoC script automatically starts QEMU with the crafted payload

./run.sh

```

The [`stage2.c`](https://github.com/bikini/exploitarium/blob/main/stage2.c) component executes within the guest and triggers the vulnerable mailbox code path, resulting in a marker file appearing on the host:

```

/tmp/qemu_cxl_escape_marker

```

### Implications for Virtualization Security

This escape vector is particularly significant because it bypasses the guest/host boundary through **emulated hardware interfaces** rather than CPU virtualization mechanisms. The mailbox implementation's host-privileged execution context provides a direct path from guest-controlled input to host code execution.

---

## Comparative Analysis of Escape Techniques

| Technique | Isolation Layer | Primary Weakness | Privilege Achieved |
|-----------|---------------|------------------|-------------------|
| **Docker `cp` escape** | Container filesystem | TOCTOU race in path validation | Host filesystem write |
| **Gitea act_runner escape** | Container namespaces | Configuration injection | Host namespace access |
| **QEMU CXL mailbox escape** | Hardware emulation | Unprivileged emulation code | Arbitrary host code execution |

All three share an architectural pattern: **trusted components accept input from untrusted contexts without充分 isolation of side effects**. The Docker CLI trusts the container filesystem state during extraction; the act_runner trusts workflow-defined container options; QEMU's CXL emulation trusts guest-supplied mailbox commands.

---

## Reproduction and Source Files

| Vulnerability | Key Files | Repository Path |
|-------------|-----------|---------------|
| Docker `cp` escape | [`poc.sh`](https://github.com/bikini/exploitarium/blob/main/poc.sh), [`README.md`](https://github.com/bikini/exploitarium/blob/main/README.md) | `docker-cp-copyout-destination-escape/` |
| Gitea act_runner escape | [`poc.py`](https://github.com/bikini/exploitarium/blob/main/poc.py), [`README.md`](https://github.com/bikini/exploitarium/blob/main/README.md) | `gitea-act-runner-container-options-poc/` |
| QEMU CXL escape | [`run.sh`](https://github.com/bikini/exploitarium/blob/main/run.sh), [`stage2.c`](https://github.com/bikini/exploitarium/blob/main/stage2.c), [`README.md`](https://github.com/bikini/exploitarium/blob/main/README.md) | `qemu-cxl-type3-mailbox-escape-poc/` |

Each directory contains complete reproduction instructions and source code. The README files in `bikini/exploitarium` provide line-by-line analysis of the vulnerable code paths and exploitation mechanics.

---

## Summary

- **Docker `cp` escape**: Race condition between path validation and tar extraction enables arbitrary host file writes via symlink manipulation.
- **Gitea act_runner escape**: Unsanitized `container.options` allow namespace and capability escalation equivalent to privileged mode.
- **QEMU CXL mailbox escape**: Guest-controlled hardware emulation interfaces execute with host privileges, enabling full VM escape.

These **container and virtualization escape vulnerabilities** archived in the Exploitarium repository demonstrate that isolation failures often occur at trust boundaries between host services and guest-controlled inputs, not just in core virtualization mechanisms.

---

## Frequently Asked Questions

### What makes the Docker `cp` escape a race condition?

The vulnerability requires precise timing: the container must create a symlink **after** Docker's filesystem walk observes a directory path but **before** the tar extraction processes that path entry. This TOCTOU window allows the prefix check to validate a path that will resolve to a different location during actual file creation.

### Can the Gitea act_runner escape be mitigated by disabling privileged containers?

No. The vulnerability specifically exploits that `Privileged: false` does not prevent individual dangerous options. The runner's `mergeContainerConfigs()` function preserves `PidMode=host`, `IpcMode=host`, `CapAdd=ALL`, and `SecurityOpt=unconfined` even when privileged mode is disabled, achieving equivalent isolation breakdown.

### Why is the QEMU CXL escape significant for virtualization security?

Traditional VM escapes target CPU virtualization bugs or device driver vulnerabilities. The CXL mailbox escape demonstrates that **emulated hardware interfaces** present an equally serious attack surface, as they run with host privileges and process guest-controlled input without adequate sandboxing.

### Are these vulnerabilities patched in upstream projects?

The Exploitarium repository archives PoCs for security research and defense purposes. Consult the individual README files in `docker-cp-copyout-destination-escape/`, `gitea-act-runner-container-options-poc/`, and `qemu-cxl-type3-mailbox-escape-poc/` for disclosure timelines and patch status.