Excessive container capabilities

Allow only required Linux capabilities and test the service after reducing privileges.

Description

Do not grant unnecessary Linux capabilities to a Docker Compose service. Capabilities permit privileged kernel operations, so granting more than required can weaken isolation.

Using cap_add with ALL can grant system privileges the application does not need. Containers should retain only required capabilities and drop unnecessary ones where possible.

Potential impact

  • Additional privileges can be abused in container escape or system misuse attempts.
  • An application vulnerability may have a larger impact.
  • Effects on the host or other containers depend on the actual privileges and other isolation settings.

Remediation

  • Minimize cap_add and specify only capabilities the service requires.
  • Use cap_drop to remove unnecessary capabilities where possible.
  • Document each service’s needs to prevent repeated excessive grants.

Examples

Before

yaml
services:
  webapp:
    image: nginx:latest
    cap_add:
      - ALL

After

yaml
services:
  webapp:
    image: nginx:latest
    cap_drop:
      - ALL

Explanation:

  • Before: All capabilities are added, unnecessarily broadening system privileges.
  • After: All capabilities are dropped. This can also remove privileges needed for image initialization or execution; test the service and restore only those it requires.

References