2024-07-11 12:42:37 -04:00
|
|
|
## Copyright (C) 2012 - 2024 ENCRYPTED SUPPORT LP <adrelanos@whonix.org>
|
|
|
|
## See the file COPYING for copying conditions.
|
|
|
|
|
|
|
|
## See the following links for a community discussion and overview regarding the selections.
|
|
|
|
## https://forums.whonix.org/t/blacklist-more-kernel-modules-to-reduce-attack-surface/7989
|
|
|
|
## https://madaidans-insecurities.github.io/guides/linux-hardening.html#kasr-kernel-modules
|
|
|
|
|
|
|
|
## Blacklisting prevents kernel modules from automatically starting.
|
|
|
|
## Disabling prohibits kernel modules from starting.
|
|
|
|
|
|
|
|
## CD-ROM/DVD:
|
|
|
|
## Blacklist CD-ROM and DVD modules.
|
|
|
|
## Do not disable by default for potential future ISO plans.
|
2024-07-13 09:29:52 -04:00
|
|
|
##
|
2024-07-11 12:42:37 -04:00
|
|
|
## https://nvd.nist.gov/vuln/detail/CVE-2018-11506
|
|
|
|
## https://forums.whonix.org/t/blacklist-more-kernel-modules-to-reduce-attack-surface/7989/31
|
2024-07-13 09:29:52 -04:00
|
|
|
##
|
2024-07-11 12:42:37 -04:00
|
|
|
blacklist cdrom
|
|
|
|
blacklist sr_mod
|
2024-07-13 09:29:52 -04:00
|
|
|
##
|
2024-07-11 12:42:37 -04:00
|
|
|
#install cdrom /usr/bin/disabled-cdrom-by-security-misc
|
|
|
|
#install sr_mod /usr/bin/disabled-cdrom-by-security-misc
|
|
|
|
|
|
|
|
## Miscellaneous:
|
2024-07-13 09:29:52 -04:00
|
|
|
##
|
2024-07-11 12:42:37 -04:00
|
|
|
## https://git.launchpad.net/ubuntu/+source/kmod/tree/debian/modprobe.d/blacklist.conf?h=ubuntu/disco
|
|
|
|
## https://git.launchpad.net/ubuntu/+source/kmod/tree/debian/modprobe.d/blacklist-ath_pci.conf?h=ubuntu/disco
|
2024-07-13 09:29:52 -04:00
|
|
|
##
|
2024-07-11 12:42:37 -04:00
|
|
|
blacklist amd76x_edac
|
2024-07-20 01:03:21 -04:00
|
|
|
blacklist ath_pci
|
2024-07-11 12:42:37 -04:00
|
|
|
blacklist evbug
|
|
|
|
blacklist pcspkr
|
|
|
|
blacklist snd_aw2
|
|
|
|
blacklist snd_intel8x0m
|
|
|
|
blacklist snd_pcsp
|
|
|
|
blacklist usbkbd
|
|
|
|
blacklist usbmouse
|