https://media.ccc.de/v/39c3-escaping-containment-a-security-analysis-of-freebsd-jails media.ccc.de logo, a lucky cat holding a play icon System Light Dark News RSS, last 100 Podcast feed of the last two years SD quality Podcast audio feed of the last year Podcast archive feed, everything older than two years SD quality Podcast feeds for 39c3 mp4 SD quality webm SD quality opus mp3 vtt [ ] News RSS, last 100 Podcast feed of the last two years SD quality Podcast audio feed of the last year Podcast archive feed, everything older than two years SD quality Podcast feeds for 39c3 mp4 SD quality webm SD quality opus mp3 vtt 1. browse 2. congress 3. 2025 4. event conference logo Escaping Containment: A Security Analysis of FreeBSD Jails ilja and Michael Smith Fuse Security Playlists: '39c3' videos starting here / audio * 59 min * 2025-12-27 * 2025-12-29 * 1.5k * Fahrplan FreeBSD's jail mechanism promises strong isolation--but how strong is it really? In this talk, we explore what it takes to escape a compromised FreeBSD jail by auditing the kernel's attack surface, identifying dozens of vulnerabilities across exposed subsystems, and developing practical proof-of-concept exploits. We'll share our findings, demo some real escapes, and discuss what they reveal about the challenges of maintaining robust OS isolation. FreeBSD's jail feature is one of the oldest and most mature OS-level isolation mechanisms in use today, powering hosting environments, container frameworks, and security sandboxes. But as with any large and evolving kernel feature, complexity breeds opportunity. This research asks a simple but critical question: If an attacker compromises root inside a FreeBSD jail, what does it take to break out? To answer that, we conducted a large-scale audit of FreeBSD kernel code paths accessible from within a jail. We systematically examined privileged operations, capabilities, and interfaces that a jailed process can still reach, hunting for memory safety issues, race conditions, and logic flaws. The result: roughly 50 distinct issues uncovered across multiple kernel subsystems, ranging from buffer overflows and information leaks to unbounded allocations and reference counting errors--many of which could crash the system or provide vectors for privilege escalation beyond the jail. We've developed proof-of-concept exploits and tools to demonstrate some of these vulnerabilities in action. We've responsibly disclosed our findings to the FreeBSD security team and are collaborating with them on fixes. Our goal isn't to break FreeBSD, but to highlight the systemic difficulty of maintaining strict isolation in a large, mature codebase. This talk will present our methodology, tooling, and selected demos of real jail escapes. We'll close with observations about kernel isolation boundaries, lessons learned for other OS container systems, and a call to action for hardening FreeBSD's jail subsystem against the next generation of threats. Licensed to the public under http://creativecommons.org/licenses/by/ 4.0 Download Video * AV1 * MP4 * WebM Download 1080p eng-deu 439 MB Download 576p eng-deu 209 MB Download 1080p eng-deu 773 MB Download 576p eng-deu 193 MB Download 1080p eng-deu 514 MB These files contain multiple languages. This Talk was translated into multiple languages. The files available for download contain all languages as separate audio-tracks. Most desktop video players allow you to choose between them. Please look for "audio tracks" in your desktop video player. Subtitles eng Help us to improve these subtitles! Audio Download mp3 eng 54 MB Download mp3 deu 54 MB Download opus eng 32 MB Download opus deu 37 MB Embed [