Container and Virtualization Escape Vulnerabilities in the Exploitarium Repository

The Exploitarium repository archives three container and virtualization escape vulnerabilities: a Docker cp race condition, a Gitea act_runner namespace bypass, and a QEMU CXL Type-3 mailbox exploit.

The bikini/exploitarium repository is a curated collection of proof-of-concept (PoC) exploits that demonstrate how container and virtualization isolation can be broken through trusted-host interaction failures. Each PoC targets a specific architectural flaw where untrusted code inside a container or VM manipulates host-side resources to achieve escape. This article examines all three archived container and virtualization escape vulnerabilities with technical implementation details from the source code.


Docker cp Copy-Out Destination Escape (Race Condition)

The Docker cp escape exploits a time-of-check to time-of-use (TOCTOU) race in the container-to-host file copy mechanism.

How the Vulnerability Works

In docker-cp-copyout-destination-escape/README.md, the vulnerability is described as a race between three operations:

  1. The Docker CLI resolves the host destination path and walks the container filesystem
  2. The daemon streams the container's contents via CopyFromContainer
  3. The CLI extracts the tar archive locally using archive.CopyTo

The extraction code performs a prefix check with strings.HasPrefix to verify that extracted files stay within the destination directory. However, this check can be bypassed when a malicious container replaces a directory with a symlink after the path walk observes it but before the tar entry is processed.


# Run the PoC (requires Docker)

chmod +x poc.sh
HOST_BASE=/tmp/docker-cp-copyout-repro ./poc.sh

The PoC creates a container where /tmp/src is being copied. During the copy operation, the container replaces a subdirectory with a symlink pointing to ../dst2, causing the host-side extraction to write the marker file outside the intended destination:


success=yes
requested_destination=/tmp/docker-cp-copyout-repro/dst
outside_marker_path=/tmp/docker-cp-copyout-repro/dst2/marker
outside_marker_value=container-controlled-host-marker

Root Cause

The strings.HasPrefix validation in the extraction logic fails to account for path traversal through symlinks created mid-operation. The raw prefix check treats the resolved symlink target as valid because it technically shares the destination prefix, even when it escapes the intended bounds.


Gitea act_runner container.options Host-Namespace Escape

This vulnerability demonstrates how configuration injection can bypass container isolation even when Privileged mode is explicitly disabled.

The Attack Vector

The Gitea act_runner parses workflow-defined container.options and merges them into Docker run configurations via mergeContainerConfigs(). According to gitea-act-runner-container-options-poc/README.md, the runner preserves dangerous fields without adequate sanitization:

  • PidMode=host — shares the host PID namespace
  • IpcMode=host — shares the host IPC namespace
  • CapAdd=ALL — grants all Linux capabilities
  • SecurityOpt=unconfined — disables security profiles
python3 poc.py --runner ./act_runner --image ubuntu:22.04

The PoC constructs a workflow that requests these options while keeping Privileged: false, which the runner accepts. Inside the job container, the exploit uses nsenter to enter the host namespaces and create a marker file:


[+] verified host marker:
uid=0(root) gid=0(root) groups=0(root)
gitea-act-runner-container-options-poc-ok

Why Privileged=False Doesn't Protect

The runner's threat model assumes that Privileged: false provides isolation, but the container.options merge logic allows equivalent privilege escalation through individual capability grants and namespace sharing. As implemented in bikini/exploitarium, the PoC proves that namespace isolation can be dismantled option-by-option without triggering the privileged container warning.


QEMU CXL Type-3 Mailbox Escape (Virtualization Layer)

The third archived vulnerability targets hardware emulation code running at host privilege level, demonstrating that virtualization escapes need not rely on traditional hypervisor bugs.

CXL Mailbox Mechanism Exploitation

Compute Express Link (CXL) Type-3 devices expose a mailbox interface for configuration and management. In QEMU, this mailbox handling runs with full host privileges. The PoC in qemu-cxl-type3-mailbox-escape-poc/ crafts mailbox interactions that cause arbitrary code execution:


# The PoC script automatically starts QEMU with the crafted payload

./run.sh

The stage2.c component executes within the guest and triggers the vulnerable mailbox code path, resulting in a marker file appearing on the host:


/tmp/qemu_cxl_escape_marker

Implications for Virtualization Security

This escape vector is particularly significant because it bypasses the guest/host boundary through emulated hardware interfaces rather than CPU virtualization mechanisms. The mailbox implementation's host-privileged execution context provides a direct path from guest-controlled input to host code execution.


Comparative Analysis of Escape Techniques

Technique Isolation Layer Primary Weakness Privilege Achieved
Docker cp escape Container filesystem TOCTOU race in path validation Host filesystem write
Gitea act_runner escape Container namespaces Configuration injection Host namespace access
QEMU CXL mailbox escape Hardware emulation Unprivileged emulation code Arbitrary host code execution

All three share an architectural pattern: trusted components accept input from untrusted contexts without充分 isolation of side effects. The Docker CLI trusts the container filesystem state during extraction; the act_runner trusts workflow-defined container options; QEMU's CXL emulation trusts guest-supplied mailbox commands.


Reproduction and Source Files

Vulnerability Key Files Repository Path
Docker cp escape poc.sh, README.md docker-cp-copyout-destination-escape/
Gitea act_runner escape poc.py, README.md gitea-act-runner-container-options-poc/
QEMU CXL escape run.sh, stage2.c, README.md qemu-cxl-type3-mailbox-escape-poc/

Each directory contains complete reproduction instructions and source code. The README files in bikini/exploitarium provide line-by-line analysis of the vulnerable code paths and exploitation mechanics.


Summary

  • Docker cp escape: Race condition between path validation and tar extraction enables arbitrary host file writes via symlink manipulation.
  • Gitea act_runner escape: Unsanitized container.options allow namespace and capability escalation equivalent to privileged mode.
  • QEMU CXL mailbox escape: Guest-controlled hardware emulation interfaces execute with host privileges, enabling full VM escape.

These container and virtualization escape vulnerabilities archived in the Exploitarium repository demonstrate that isolation failures often occur at trust boundaries between host services and guest-controlled inputs, not just in core virtualization mechanisms.


Frequently Asked Questions

What makes the Docker cp escape a race condition?

The vulnerability requires precise timing: the container must create a symlink after Docker's filesystem walk observes a directory path but before the tar extraction processes that path entry. This TOCTOU window allows the prefix check to validate a path that will resolve to a different location during actual file creation.

Can the Gitea act_runner escape be mitigated by disabling privileged containers?

No. The vulnerability specifically exploits that Privileged: false does not prevent individual dangerous options. The runner's mergeContainerConfigs() function preserves PidMode=host, IpcMode=host, CapAdd=ALL, and SecurityOpt=unconfined even when privileged mode is disabled, achieving equivalent isolation breakdown.

Why is the QEMU CXL escape significant for virtualization security?

Traditional VM escapes target CPU virtualization bugs or device driver vulnerabilities. The CXL mailbox escape demonstrates that emulated hardware interfaces present an equally serious attack surface, as they run with host privileges and process guest-controlled input without adequate sandboxing.

Are these vulnerabilities patched in upstream projects?

The Exploitarium repository archives PoCs for security research and defense purposes. Consult the individual README files in docker-cp-copyout-destination-escape/, gitea-act-runner-container-options-poc/, and qemu-cxl-type3-mailbox-escape-poc/ for disclosure timelines and patch status.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →