Description
NET_RAW is a Linux capability allowing network functions such as raw and packet sockets. If restrictions are absent and a container actually holds it, a compromised process can misuse it. A policy that does not require dropping NET_RAW does not automatically add it to every container.
PodSecurityPolicy was removed in Kubernetes 1.25. Use Pod Security Admission or a policy engine for the required restrictions on current clusters.
Potential impact
- Unnecessary packet generation or manipulation can be used in network attacks.
- Dropping required capabilities can disrupt normal application functions.
Remediation
- Where compatible, drop all capabilities and permit only those required; at minimum, drop unneeded NET_RAW. Check effective runtime permissions and application behavior.
- Enforce the requirements with current admission policy. Do not directly use the legacy PSP required_drop_capabilities examples as policy for current clusters.
Examples
These legacy excerpts show only part of the removed PSP configuration. Other required fields and authorization to use the policy are omitted. The after value ALL requires dropping other capabilities as well as NET_RAW.
Before
hcl
resource "kubernetes_pod_security_policy" "policy" {
metadata {
name = "terraform-example"
}
spec {
required_drop_capabilities = [
"KILL",
"SYS_TIME",
]
}
}
After
hcl
resource "kubernetes_pod_security_policy" "policy" {
metadata {
name = "terraform-example"
}
spec {
required_drop_capabilities = [
"ALL",
]
}
}
Explanation:
- Before: KILL and SYS_TIME must be dropped, but NET_RAW is not explicitly included.
- After: All capabilities must be dropped. Check that the application works under this restriction.