Skip to content
Back to skills

Cis Docker V170 5.29

ASecurity

Ensure that the PIDs cgroup limit is used

  • 2,182 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added September 3, 2026
securitygobashdocker

Security analysis

A100/100

Scanned September 3, 2026

npx -y skills add CyberStrikeus/CyberStrike --skill cis-docker-v170-5.29 --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cis Docker V170 5.29?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Cis Docker V170 5.29
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/cyberstrikeus-cis-docker-v170-5-29/badge)](https://www.skillsdirectory.com/skills/cyberstrikeus-cis-docker-v170-5-29)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: cis-docker-v170-5.29
description: "Ensure that the PIDs cgroup limit is used"
category: cis-docker
version: "1.7.0"
author: cyberstrike-official
tags: [cis, docker, runtime, pids, cgroup, dos]
cis_id: "5.29"
cis_benchmark: "CIS Docker Benchmark v1.7.0"
tech_stack: [docker]
cwe_ids: []
chains_with: []
prerequisites: []
severity_boost: {}
---

# CIS Docker Benchmark v1.7.0 - Control 5.29

## Profile Applicability

- **Level:** 1
- **Type:** Manual
- **Platform:** Docker - Linux

## Description

You should use the `--pids-limit` flag at container runtime.

## Rationale

Attackers could launch a fork bomb with a single command inside the container. This fork bomb could crash the entire system and would require a restart of the host to make the system functional again. Using the PIDs cgroup parameter `--pids-limit` would prevent this kind of attack by restricting the number of forks that can happen inside a container within a specified time frame.

## Impact

Set the PIDs limit value as appropriate. Incorrect values might leave containers unusable.

## Audit Procedure

You should run the command below and ensure that `PidsLimit` is not set to 0 or -1. A `PidsLimit` of 0 or -1 means that any number of processes can be forked concurrently inside the container.

```bash
docker ps --quiet --all | xargs docker inspect --format '{{ .Id }}: PidsLimit={{ .HostConfig.PidsLimit }}'
```

## Remediation

Use `--pids-limit` flag with an appropriate value when launching the container.

For example:

```bash
docker run -it --pids-limit 100 <Image ID>
```

In the above example, the number of processes allowed to run at any given time is set to 100. After a limit of 100 concurrently running processes is reached, Docker would restrict any new process creation.

## Default Value

The Default value for `--pids-limit` is 0 which means there is no restriction on the number of forks. Note that the PIDs cgroup limit works only for kernel versions 4.3 and higher.

## References

1. https://docs.docker.com/engine/reference/commandline/run/

## CIS Controls

**v8:**

- **4 Secure Configuration of Enterprise Assets and Software**
  - Establish and maintain the secure configuration of enterprise assets (end-user devices, including portable and mobile; network devices; non-computing/IoT devices; and servers) and software (operating systems and applications).

**v7:**

- **5.2 Maintain Secure Images**
  - Maintain secure images or templates for all systems in the enterprise based on the organization's approved configuration standards. Any new system deployment or existing system that becomes compromised should be imaged using one of those images or templates.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…