Update README.md

This commit is contained in:
raja-grewal 2022-07-07 09:28:30 +00:00 committed by GitHub
parent f0511635a9
commit 28381e81d4
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -149,6 +149,11 @@ of multiple vulnerabilities so it is blacklisted.
* The MSR kernel module is blacklisted to prevent CPU MSRs from being
abused to write to arbitrary memory.
* Disables a large array of uncommon file systems and network file systems that reduces the attack surface especially against legacy approaches.
* Disables the use of CD-ROM devices by default.
* Provides some blocking of the interface between the [Intel Management Engine (ME)](https://www.kernel.org/doc/html/latest/driver-api/mei/mei.html) and the OS.
### Other
* A systemd service clears the System.map file on boot as these contain kernel