Review low port mappings and privileges

Publish only required ports and remove network privileges the service does not need.

Description

Ports from 1 through 1023 are traditionally used by system services. Distinguish the port published on the host from the port where the container listens; mapping a low port does not itself grant the container root privileges.

The network namespace’s ip_unprivileged_port_start setting also affects the privileges required to listen on low ports. Where practical, use higher ports for ordinary applications and remove unnecessary NET_BIND_SERVICE capability.

Potential impact

  • Unnecessary network capabilities increase the privileges available after a service is compromised.
  • Services published more broadly than needed may receive external access attempts.
  • Changing ports without checking protocol requirements can interrupt the service.

Remediation

  • Check the need for both the host port and the container listening port. Consider ports at or above 1024 for applications that support changing them.
  • Drop NET_BIND_SERVICE when it is unnecessary, and test normal operation with the actual user and namespace settings.
  • Preserve required protocol ports, such as those used by DHCP, and restrict network access. A high port does not replace authentication or firewall controls.

Examples

DHCP clients send requests to server UDP port 67. The second example is for a separate application configured to listen on 6700/udp, not a replacement configuration for the DHCP server. Set APP_IMAGE to that application image.

Before

yaml
services:
  dhcpd:
    image: networkboot/dhcpd:latest
    ports:
      - "67:67/udp"

After

yaml
services:
  app:
    image: ${APP_IMAGE:?set APP_IMAGE}
    ports:
      - "6700:6700/udp"
    cap_drop:
      - NET_BIND_SERVICE

Explanation:

  • Before: The DHCP server’s UDP port 67 is published. Review access and actual privileges while accounting for the required protocol port.
  • After: An application with a configurable port listens on a higher port and drops an unnecessary capability. Restrict its network exposure separately.

References