Container lacks no-new-privileges protection

no-new-privileges restricts acquiring additional privileges by executing a new program.

Description

Setting no-new-privileges:true in Docker Compose security_opt restricts privilege gains from setuid, setgid and file capabilities when a process executes a new program. Without this protection, those escalation paths may remain available.

The option does not remove existing privileges or prevent every exploit. Use it alongside least-privilege execution.

Potential impact

  • A compromised process may gain greater privileges by executing a program that provides them.
  • The resulting access can extend damage to additional data or resources.

Remediation

  • Set no-new-privileges:true in the service’s security_opt.
  • Identify startup or runtime operations that depend on privilege escalation and adapt them to work with minimal privileges.
  • Review privileged, added capabilities and sensitive mounts, then test the application after the change.

Examples

The example requires the actual build context and service.dockerfile.

Before

yaml
version: "3.4"
services:
  app:
    build:
      context: ./
      dockerfile: service.dockerfile
    security_opt:
      - no-new-privileges:false

Protection against privilege gains through execution of a new program is disabled.

After

yaml
version: "3.4"
services:
  app:
    build:
      context: ./
      dockerfile: service.dockerfile
    security_opt:
      - no-new-privileges:true

The service enables no-new-privileges:true. Confirm that its required startup and runtime operations work under this restriction.

References