Update control

This commit is contained in:
madaidan 2020-02-12 18:43:19 +00:00 committed by GitHub
parent 700c7ed908
commit 2796c2dd00
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

7
debian/control vendored
View File

@ -66,12 +66,7 @@ Description: enhances misc security settings
* Kernel Page Table Isolation is enabled to mitigate Meltdown and increase
KASLR effectiveness.
.
* SMT is disabled as it can be used to exploit the MDS and other
vulnerabilities.
.
* All mitigations for the MDS vulnerability are enabled.
.
* Enables mitigations for the L1TF (L1 Terminal Fault) vulnerability.
* Enables all mitigations for CPU vulnerabilities and disables SMT.
.
* A systemd service clears System.map on boot as these contain kernel symbols
that could be useful to an attacker.