5.28 Use PIDs cgroup limit

Information

https://github.com/docker/docker/pull/18697
2.https://docs.docker.com/engine/reference/commandline/run/

Solution

Use --pids-limit flag while launching the container with an appropriate value.For example,docker run -it --pids-limit 100 <Image_ID>In the above example, the number of processes allowed to run at any given time is set to
100. After a limit of 100 concurrently running processes is reached, docker would restrict
any new process creation.Impact-Set the PIDs limit value as appropriate. Incorrect values might leave the containers
unusable.Default Value-The Default value for --pids-limit is 0 which means there is no restriction on the number
of forks. Also, note that PIDs cgroup limit works only for the kernel versions 4.3+.

See Also

https://workbench.cisecurity.org/files/517

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-5

Plugin: Unix

Control ID: 5c0a81ded3653596b42a461efaece9a30ccdfad35e8f40a66f206e81964be580