PodSecurityPolicy permits privilege escalation

A PodSecurityPolicy that permits privilege escalation does not restrict gaining additional permissions through executable files.

Description

A legacy PodSecurityPolicy that permits allowPrivilegeEscalation allows container configurations that can gain additional privileges through setuid, setgid, or file capabilities when executing programs. Restrict this to false for ordinary workloads. It does not remove existing permissions or prevent every kernel exploit.

PSP was deprecated in Kubernetes 1.21 and removed in 1.25. On current clusters, use the Restricted policy in Pod Security Admission or another admission policy together with workload security contexts.

Potential impact

  • A compromised process may have more opportunities to use executables that grant additional privileges.
  • Excessive permissions or host access can increase the impact of a container compromise.

Remediation

  • Set allowPrivilegeEscalation: false in legacy policies and restrict privileged and unnecessary capabilities.
  • Remove privileged mode or SYS_ADMIN from actual containers before enforcing this restriction; those settings are incompatible with preventing privilege escalation.
  • Verify that the replacement policy is enforced and that applications previously relying on setuid or similar behavior still work.

Examples

These excerpts show only the relevant PSP fields for Kubernetes before 1.25. Other required policy fields are omitted.

Before

yaml
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
  name: privileged
spec:
  privileged: true
  allowPrivilegeEscalation: true

The policy permits both privileged execution and privilege escalation. Actual use depends on policy enforcement and authorization to use it.

After

yaml
apiVersion: policy/v1beta1
kind: PodSecurityPolicy
metadata:
  name: privileged
spec:
  privileged: false
  allowPrivilegeEscalation: false

Privileged execution is also prohibited so that it aligns with the intent of allowPrivilegeEscalation: false. Check that another policy cannot grant broader permissions.

References