This commit is contained in:
Patrick Schleizer 2020-01-17 03:10:56 -05:00
parent 6f8d89c6c5
commit 1304341868
No known key found for this signature in database
GPG Key ID: CB8D50BB77BB3C48

View File

@ -99,8 +99,9 @@ a target for ROP.
* The vivid kernel module is blacklisted as it's only required for testing
and has been the cause of multiple vulnerabilities.
* An initramfs hook sets the sysctl values in /etc/sysctl.d before init
is executed so sysctl hardening is enabled as early as possible.
* An initramfs hook sets the sysctl values in /etc/sysctl.conf and
/etc/sysctl.d before init is executed so sysctl hardening is enabled
as early as possible.
* The kernel panics on oopses to prevent it from continuing to run a flawed
process and to deter brute forcing.