Description
securityContext.allowPrivilegeEscalation controls whether a process can gain more privileges than its parent. Setting it to false on Linux restricts gains from executing a new program, such as a setuid binary. When omitted, it defaults to true.
It does not remove existing privileges or prevent every exploit. A value of false cannot be combined with privileged or SYS_ADMIN, so remove excessive privileges as well.
Potential impact
- A compromised process may execute a program that gives it greater privileges.
- Damage can extend to files or resources accessible with those additional privileges.
Remediation
- Explicitly set
allowPrivilegeEscalation: falsefor Linux containers and init containers. - Remove unnecessary
privileged,SYS_ADMINand sensitive host mounts, and consider non-root execution. - Adapt initialization that relies on privilege escalation and test application behavior in the actual deployment.
Examples
The image address is a placeholder. Apply the setting to the actual Linux application image and workload template.
Before
apiVersion: v1
kind: Pod
metadata:
name: pod2
spec:
containers:
- name: app
image: images.my-company.example/app:v4
securityContext:
allowPrivilegeEscalation: true
The container does not restrict acquiring additional privileges through execution of a new program.
After
apiVersion: v1
kind: Pod
metadata:
name: pod1
spec:
containers:
- name: app
image: images.my-company.example/app:v4
securityContext:
allowPrivilegeEscalation: false
Privilege escalation is restricted. Review privileges already granted and other security settings as well.