CVE-2019-5736 - Escape from Docker and Kubernetes containers to root on host

This scenario demos has been taken from Thanks to Nick Frichette

This is a Go implementation of CVE-2019-5736, a container escape for Docker. The exploit works by overwriting and executing the host systems runc binary from within the container.

How does the exploit work?

Example of malicious Docker image
