Disable more Intel Management Engine (ME) modules

This commit is contained in:
Raja Grewal 2024-07-15 22:21:20 +10:00
parent 5ba5a85ad0
commit 22ba7a7c39
No known key found for this signature in database
GPG Key ID: 92CA473C156B64C4

View File

@ -68,7 +68,17 @@ install gnss-usb /usr/bin/disabled-gps-by-security-misc
## https://www.kernel.org/doc/html/latest/driver-api/mei/mei.html
##
install mei /usr/bin/disabled-intelme-by-security-misc
install mei-gsc /usr/bin/disabled-intelme-by-security-misc
install mei_gsc_proxy /usr/bin/disabled-intelme-by-security-misc
install mei_hdcp /usr/bin/disabled-intelme-by-security-misc
install mei-me /usr/bin/disabled-intelme-by-security-misc
install mei_phy /usr/bin/disabled-intelme-by-security-misc
install mei_pxp /usr/bin/disabled-intelme-by-security-misc
install mei-txe /usr/bin/disabled-intelme-by-security-misc
install mei-vsc-hw /usr/bin/disabled-intelme-by-security-misc
install mei-vsc /usr/bin/disabled-intelme-by-security-misc
install mei_wdt /usr/bin/disabled-intelme-by-security-misc
install microread_mei /usr/bin/disabled-intelme-by-security-misc
## Network File Systems:
## Disable uncommon network file systems to reduce attack surface.