Description
Linux capabilities such as NET_ADMIN and SYS_TIME allow specific privileged operations, including network configuration or system-time changes. Adding unnecessary capabilities increases the actions available to an attacker who compromises the application.
The effect depends on the capability, namespaces and host access. Review the default capability set too; not every application needs all defaults.
Potential impact
A compromised process may perform unnecessary network or system operations or exploit other isolation weaknesses. Removing a required capability without testing can also disrupt application functions.
Remediation
- Remove unnecessary capabilities from securityContext.capabilities.add.
- Where possible, use drop: [ALL] and add back only required capabilities. Document each exception’s purpose and scope.
- Combine this with non-root execution and protection against privilege escalation, and verify required functions.
Examples
These Pod examples compare added capabilities. Apply changes to the actual target Pod and check the image’s permission requirements.
Before
apiVersion: v1
kind: Pod
metadata:
name: pod2
spec:
containers:
- name: app
image: images.my-company.example/app:v4
securityContext:
allowPrivilegeEscalation: false
capabilities:
add: ["NET_ADMIN", "SYS_TIME"]
This adds NET_ADMIN and SYS_TIME. allowPrivilegeEscalation: false does not remove capabilities already granted.
After
apiVersion: v1
kind: Pod
metadata:
name: pod1
spec:
containers:
- name: app
image: images.my-company.example/app:v4
securityContext:
allowPrivilegeEscalation: false
No additional capabilities are specified. This does not remove every runtime default capability; review drop settings separately.