Description
NET_RAW is a Linux capability permitting network functions such as raw and packet sockets. Many ordinary applications do not need it, and a compromised process can misuse it if unnecessarily retained. Check runtime defaults together with added and dropped capabilities to determine effective permissions.
Potential impact
- Unnecessary packet generation or manipulation functions can be misused.
- Removing too many capabilities can affect required application behavior.
Remediation
- Add unneeded
NET_RAWtosecurity_context.capabilities.drop. Where a stricter minimum-permission setup is compatible, consider droppingALLand allowing only the capabilities that are needed. - Check capabilities added back and privileged mode, and test actual application behavior. Enforce the required criteria with Pod Security Admission or a policy engine.
Examples
These examples compare removing NET_RAW from the retained nginx configuration. Dropping every capability can affect user switching, ports or file operations, so ALL requires separate compatibility checks. Use a maintained image for deployment.
Before
hcl
resource "kubernetes_pod" "pod" {
metadata {
name = "terraform-example"
}
spec {
container {
image = "nginx:1.7.9"
name = "example"
security_context {
capabilities {}
}
}
}
}
After
hcl
resource "kubernetes_pod" "pod" {
metadata {
name = "terraform-example"
}
spec {
container {
image = "nginx:1.7.9"
name = "example"
security_context {
capabilities {
drop = ["NET_RAW"]
}
}
}
}
}
Explanation:
- Before: No explicit capabilities are dropped. Check the effective runtime defaults.
- After: NET_RAW is dropped. This does not remove every other default capability.