GHSA-hwm2-4ph6-w6m5
### Impact The `restricted` pod security policy (PSP), provided in Rancher versions from 2.0 up to and including 2.6.3, has a deviation from the [upstream](https://github.com/kubernetes/website/blob/6d22e08903d7dd44b049c4689fa882ae07f67de9/content/en/examples/policy/restricted-psp.yaml) `restricted` policy provided in Kubernetes, in which Rancher's PSP has `runAsUser` set to `runAsAny`, while upstream has `runAsUser` set to `MustRunAsNonRoot`. This allows containers to run as any user, including a privileged user (`root`), even when Rancher's `restricted` policy is enforced on a project or at cluster level. A new `restricted-noroot` PSP was created to prevent pods from running as `root` when this policy is enforced. This new policy was introduced, instead of patching the current provided `restricted` policy, in order to avoid breaking users' workloads that are using the `restricted` PSP and that might be running as a privileged user. **Note**: Running containers as `root` increases the risk of a compromised container being used by a malicious actor as an attack platform to further exploit the user's environment. It is a security best practice to avoid running containers as a privileged user and to limit its usage to workloads where it is strictly necessary. ### Patches Patched versions include release 2.6.4 and later versions. The existing `restricted` PSP in Rancher 2.6.4 was not modified and still allows containers to run as a privileged user, as explained above. This fix was not backported to previous releases. For Rancher 2.6.4 and later releases, users using the current `restricted` PSP and that want to prevent containers from running as `root`, are advised to migrate to the new `restricted-noroot` policy. Before doing this migration, it is necessary to verify if affected workloads are currently running as a privileged user and modify them accordingly to the users' own environment to run as a non-privileged user. A redeployment of the affected workload is
Properties
- ghsa_id
- GHSA-hwm2-4ph6-w6m5
- severity
- high
- summary
- Rancher's restricted PodSecurityPolicy does not prevent containers from running as a privileged user
- cve_id
- GHSA-hwm2-4ph6-w6m5
- is_ghsa_only
- true
- ghsa_published
- 2026-03-03T14:51:36Z
- source_url
- https://github.com/advisories/GHSA-hwm2-4ph6-w6m5
- ghsa_updated
- 2026-03-03T14:51:36Z
Related Entities (3)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph