Restrict the userfaultfd() syscall to root

This commit is contained in:
madaidan 2020-02-24 18:23:15 +00:00 committed by GitHub
parent c7f2537930
commit 6b64b36b01
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -133,3 +133,9 @@ kernel.sysrq=132
##
## https://lkml.org/lkml/2019/4/15/890
dev.tty.ldisc_autoload=0
## Restrict the userfaultfd() syscall to root as it can make heap sprays
## easier.
##
## https://duasynt.com/blog/linux-kernel-heap-spray
vm.unprivileged_userfaultfd=0