5.30 Do not share the host's user namespaces

Information

https://docs.docker.com/engine/reference/commandline/run/#/run
2.https://events.linuxfoundation.org/sites/events/files/slides/User%20Namespaces%20-%20ContainerCon%202015%20-%2016-9-final_0.pdf
3.https://github.com/docker/docker/pull/12648

Solution

Do not share user namespaces between host and containers.Impact-NoneDefault Value-By default, the host user namespace is shared with the containers until user namespace
support is enabled.

See Also

https://workbench.cisecurity.org/files/517

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7a.

Plugin: Unix

Control ID: 447ee2aa56ffb3e48235bfccb4c32675973538ced497425ba639a1bb133ba38f