Container and Virtualization Escape Vulnerabilities in the Exploitarium Repository
The Exploitarium repository archives three container and virtualization escape vulnerabilities: a Docker cp race condition, a Gitea act_runner namespace bypass, and a QEMU CXL Type-3 mailbox exploit.
The bikini/exploitarium repository is a curated collection of proof-of-concept (PoC) exploits that demonstrate how container and virtualization isolation can be broken through trusted-host interaction failures. Each PoC targets a specific architectural flaw where untrusted code inside a container or VM manipulates host-side resources to achieve escape. This article examines all three archived container and virtualization escape vulnerabilities with technical implementation details from the source code.
Docker cp Copy-Out Destination Escape (Race Condition)
The Docker cp escape exploits a time-of-check to time-of-use (TOCTOU) race in the container-to-host file copy mechanism.
How the Vulnerability Works
In docker-cp-copyout-destination-escape/README.md, the vulnerability is described as a race between three operations:
- The Docker CLI resolves the host destination path and walks the container filesystem
- The daemon streams the container's contents via
CopyFromContainer - The CLI extracts the tar archive locally using
archive.CopyTo
The extraction code performs a prefix check with strings.HasPrefix to verify that extracted files stay within the destination directory. However, this check can be bypassed when a malicious container replaces a directory with a symlink after the path walk observes it but before the tar entry is processed.
# Run the PoC (requires Docker)
chmod +x poc.sh
HOST_BASE=/tmp/docker-cp-copyout-repro ./poc.sh
The PoC creates a container where /tmp/src is being copied. During the copy operation, the container replaces a subdirectory with a symlink pointing to ../dst2, causing the host-side extraction to write the marker file outside the intended destination:
success=yes
requested_destination=/tmp/docker-cp-copyout-repro/dst
outside_marker_path=/tmp/docker-cp-copyout-repro/dst2/marker
outside_marker_value=container-controlled-host-marker
Root Cause
The strings.HasPrefix validation in the extraction logic fails to account for path traversal through symlinks created mid-operation. The raw prefix check treats the resolved symlink target as valid because it technically shares the destination prefix, even when it escapes the intended bounds.
Gitea act_runner container.options Host-Namespace Escape
This vulnerability demonstrates how configuration injection can bypass container isolation even when Privileged mode is explicitly disabled.
The Attack Vector
The Gitea act_runner parses workflow-defined container.options and merges them into Docker run configurations via mergeContainerConfigs(). According to gitea-act-runner-container-options-poc/README.md, the runner preserves dangerous fields without adequate sanitization:
PidMode=host— shares the host PID namespaceIpcMode=host— shares the host IPC namespaceCapAdd=ALL— grants all Linux capabilitiesSecurityOpt=unconfined— disables security profiles
python3 poc.py --runner ./act_runner --image ubuntu:22.04
The PoC constructs a workflow that requests these options while keeping Privileged: false, which the runner accepts. Inside the job container, the exploit uses nsenter to enter the host namespaces and create a marker file:
[+] verified host marker:
uid=0(root) gid=0(root) groups=0(root)
gitea-act-runner-container-options-poc-ok
Why Privileged=False Doesn't Protect
The runner's threat model assumes that Privileged: false provides isolation, but the container.options merge logic allows equivalent privilege escalation through individual capability grants and namespace sharing. As implemented in bikini/exploitarium, the PoC proves that namespace isolation can be dismantled option-by-option without triggering the privileged container warning.
QEMU CXL Type-3 Mailbox Escape (Virtualization Layer)
The third archived vulnerability targets hardware emulation code running at host privilege level, demonstrating that virtualization escapes need not rely on traditional hypervisor bugs.
CXL Mailbox Mechanism Exploitation
Compute Express Link (CXL) Type-3 devices expose a mailbox interface for configuration and management. In QEMU, this mailbox handling runs with full host privileges. The PoC in qemu-cxl-type3-mailbox-escape-poc/ crafts mailbox interactions that cause arbitrary code execution:
# The PoC script automatically starts QEMU with the crafted payload
./run.sh
The stage2.c component executes within the guest and triggers the vulnerable mailbox code path, resulting in a marker file appearing on the host:
/tmp/qemu_cxl_escape_marker
Implications for Virtualization Security
This escape vector is particularly significant because it bypasses the guest/host boundary through emulated hardware interfaces rather than CPU virtualization mechanisms. The mailbox implementation's host-privileged execution context provides a direct path from guest-controlled input to host code execution.
Comparative Analysis of Escape Techniques
| Technique | Isolation Layer | Primary Weakness | Privilege Achieved |
|---|---|---|---|
Docker cp escape |
Container filesystem | TOCTOU race in path validation | Host filesystem write |
| Gitea act_runner escape | Container namespaces | Configuration injection | Host namespace access |
| QEMU CXL mailbox escape | Hardware emulation | Unprivileged emulation code | Arbitrary host code execution |
All three share an architectural pattern: trusted components accept input from untrusted contexts without充分 isolation of side effects. The Docker CLI trusts the container filesystem state during extraction; the act_runner trusts workflow-defined container options; QEMU's CXL emulation trusts guest-supplied mailbox commands.
Reproduction and Source Files
| Vulnerability | Key Files | Repository Path |
|---|---|---|
Docker cp escape |
poc.sh, README.md |
docker-cp-copyout-destination-escape/ |
| Gitea act_runner escape | poc.py, README.md |
gitea-act-runner-container-options-poc/ |
| QEMU CXL escape | run.sh, stage2.c, README.md |
qemu-cxl-type3-mailbox-escape-poc/ |
Each directory contains complete reproduction instructions and source code. The README files in bikini/exploitarium provide line-by-line analysis of the vulnerable code paths and exploitation mechanics.
Summary
- Docker
cpescape: Race condition between path validation and tar extraction enables arbitrary host file writes via symlink manipulation. - Gitea act_runner escape: Unsanitized
container.optionsallow namespace and capability escalation equivalent to privileged mode. - QEMU CXL mailbox escape: Guest-controlled hardware emulation interfaces execute with host privileges, enabling full VM escape.
These container and virtualization escape vulnerabilities archived in the Exploitarium repository demonstrate that isolation failures often occur at trust boundaries between host services and guest-controlled inputs, not just in core virtualization mechanisms.
Frequently Asked Questions
What makes the Docker cp escape a race condition?
The vulnerability requires precise timing: the container must create a symlink after Docker's filesystem walk observes a directory path but before the tar extraction processes that path entry. This TOCTOU window allows the prefix check to validate a path that will resolve to a different location during actual file creation.
Can the Gitea act_runner escape be mitigated by disabling privileged containers?
No. The vulnerability specifically exploits that Privileged: false does not prevent individual dangerous options. The runner's mergeContainerConfigs() function preserves PidMode=host, IpcMode=host, CapAdd=ALL, and SecurityOpt=unconfined even when privileged mode is disabled, achieving equivalent isolation breakdown.
Why is the QEMU CXL escape significant for virtualization security?
Traditional VM escapes target CPU virtualization bugs or device driver vulnerabilities. The CXL mailbox escape demonstrates that emulated hardware interfaces present an equally serious attack surface, as they run with host privileges and process guest-controlled input without adequate sandboxing.
Are these vulnerabilities patched in upstream projects?
The Exploitarium repository archives PoCs for security research and defense purposes. Consult the individual README files in docker-cp-copyout-destination-escape/, gitea-act-runner-container-options-poc/, and qemu-cxl-type3-mailbox-escape-poc/ for disclosure timelines and patch status.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →