Lost along the Way: Understanding and Mitigating Path-Misresolution Threats to Container Isolation
Zhi Li, Weijie Liu, XiaoFeng Wang, Bin Yuan, Hongliang Tian, Hai Jin, Shoumeng Yan
Abstract
Filesystem isolation enforced by today's container technology has been found to be less effective in the presence of host-container interactions increasingly utilized by container tools. This weakened isolation has led to a type of path misresolution (Pamir) vulnerabilities, which have been considered to be highly risky and continuously reported over the years. In this paper, we present the first systematic study on the Pamir risk and the existing fixes to related vulnerabilities. Our research reveals that in spite of significant efforts being made to patch vulnerable container tools and address the risk, the Pamir vulnerabilities continue to be discovered, including a new vulnerability (CVE-2023-0778) we rediscovered from patched software. A key insight of our study is that the Pamir risk is inherently hard to prevent at the level of container tools, due to their heavy reliance on third-party components. While security inspections should be applied to all components to mediate host-container interactions, third-party component developers tend to believe that container tools should perform security checks before invoking their components, and are therefore reluctant to patch their code with the container-specific protection. Moreover, due to the large number of components today's container tools depend on, re-implementing all of them is impractical.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 0b18f795-97bb-4c6d-8a67-44a2674ca56fCited by top-tier papers3
- Bugs in Pods: Understanding Bugs in Container Runtime SystemsJiongchi Yu, Xiaofei Xie, Cen Zhang, Sen Chen et al.ISSTA 2024 · 3 citations
- Wormholes in the File System: Understanding the Misunderstanding of SymlinksYongheng Liu, Lei Zhang, Yuhang Zhao, Yuzhou HeUSENIX Security 2026
- Losing the Beat: Understanding and Mitigating Desynchronization Risks in Container IsolationZhi Li, Zhen Xu, Weijie Liu, XiaoFeng Wang et al.NDSS 2026
Related papers
- Death Is Not the End: a Longitudinal Study on the Impact of Automatic Updates on Container Vulnerability LifespansSimge Tekin, Octavian Suciu, Sungsu Kwag, Yonghwi Kwon et al.S&P 2026 · 1 citation
- SoK: A Comprehensive Analysis and Evaluation of Docker Container Attack and Defense MechanismsMd. Sadun Haq, Thien Duc Nguyen, Ali Saman Tosun, Franziska Vollmer et al.S&P 2024 · 17 citations
- Automating Dockerfile Refactoring to Multi-stage BuildsDongjin Chen, Wenhua Yang, Minxue Pan, Yu ZhouFSE 2026
- KIT: Testing OS-Level Virtualization for Functional Interference BugsCongyu Liu, Sishuai Gong, Pedro FonsecaASPLOS 2023 · 16 citations
- Unsafe at Any Copy: Name Collisions from Mixing Case SensitivitiesAditya Basu, John Sampson, Zhiyun Qian, Trent JaegerFAST 2023 · 4 citations
