Kubernetes container permits privilege escalation

Restrict additional privilege gains and run Linux containers with only the permissions they need.

Description

securityContext.allowPrivilegeEscalation controls whether a process can gain more privileges than its parent. Setting it to false on Linux restricts gains from executing a new program, such as a setuid binary. When omitted, it defaults to true.

It does not remove existing privileges or prevent every exploit. A value of false cannot be combined with privileged or SYS_ADMIN, so remove excessive privileges as well.

Potential impact

  • A compromised process may execute a program that gives it greater privileges.
  • Damage can extend to files or resources accessible with those additional privileges.

Remediation

  • Explicitly set allowPrivilegeEscalation: false for Linux containers and init containers.
  • Remove unnecessary privileged, SYS_ADMIN and sensitive host mounts, and consider non-root execution.
  • Adapt initialization that relies on privilege escalation and test application behavior in the actual deployment.

Examples

The image address is a placeholder. Apply the setting to the actual Linux application image and workload template.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: pod2
spec:
  containers:
    - name: app
      image: images.my-company.example/app:v4
      securityContext:
        allowPrivilegeEscalation: true

The container does not restrict acquiring additional privileges through execution of a new program.

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: pod1
spec:
  containers:
    - name: app
      image: images.my-company.example/app:v4
      securityContext:
        allowPrivilegeEscalation: false

Privilege escalation is restricted. Review privileges already granted and other security settings as well.

References