5.30 Do not share the host's user namespaces

Information

Do not share the host's user namespaces with thecontainers.

Rationale:

User namespaces ensure that a root process inside the container will be mapped to a non-root process outside the container. Sharing the user namespaces of the host with the containerthus does not isolate users on the host with users on the containers.

Solution

Do not share user namespaces between host and containers.

Impact:

None

Default Value:

By default, the host user namespace is shared with the containers until user namespace support is enabled.

See Also

https://workbench.cisecurity.org/files/1476

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7a.

Plugin: Unix

Control ID: 3f42fc03152cda8f1cef3dd70cee9db499d30be0d8763a94dd029976a074b544