Description
Ports from 1 through 1023 are traditionally used by system services. Distinguish the port published on the host from the port where the container listens; mapping a low port does not itself grant the container root privileges.
The network namespace’s ip_unprivileged_port_start setting also affects the privileges required to listen on low ports. Where practical, use higher ports for ordinary applications and remove unnecessary NET_BIND_SERVICE capability.
Potential impact
- Unnecessary network capabilities increase the privileges available after a service is compromised.
- Services published more broadly than needed may receive external access attempts.
- Changing ports without checking protocol requirements can interrupt the service.
Remediation
- Check the need for both the host port and the container listening port. Consider ports at or above 1024 for applications that support changing them.
- Drop
NET_BIND_SERVICEwhen it is unnecessary, and test normal operation with the actual user and namespace settings. - Preserve required protocol ports, such as those used by DHCP, and restrict network access. A high port does not replace authentication or firewall controls.
Examples
DHCP clients send requests to server UDP port 67. The second example is for a separate application configured to listen on 6700/udp, not a replacement configuration for the DHCP server. Set APP_IMAGE to that application image.
Before
services:
dhcpd:
image: networkboot/dhcpd:latest
ports:
- "67:67/udp"
After
services:
app:
image: ${APP_IMAGE:?set APP_IMAGE}
ports:
- "6700:6700/udp"
cap_drop:
- NET_BIND_SERVICE
Explanation:
- Before: The DHCP server’s UDP port 67 is published. Review access and actual privileges while accounting for the required protocol port.
- After: An application with a configurable port listens on a higher port and drops an unnecessary capability. Restrict its network exposure separately.