Escape from a bind mount

Jann Horn jann at
Thu Sep 22 14:34:21 UTC 2016

On Thu, Sep 22, 2016 at 04:23:11PM +0200, Gandalf Corvotempesta wrote:
> 2016-09-22 15:48 GMT+02:00 Jann Horn <jann at>:
> > It shouldn't be possible to escape from bind mounts anymore. That was a
> > bug, and it was fixed.
> > Where do the docs mention this? We should probably ask them to fix that.
> Is this also backported to older kernel versions? From which kernel
> version is fixed ?

$ git describe --contains 397d425d

It was fixed in kernel 4.3.

The fix was backported to all longterm stable kernels listed at
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: Digital signature
URL: <>

More information about the Containers mailing list