Set efi_pstore.pstore_disable=1

This commit is contained in:
raja-grewal 2025-03-16 03:30:04 +00:00 committed by GitHub
parent f643ebc2f9
commit df2fc2cf6b
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 15 additions and 0 deletions

View file

@ -226,6 +226,9 @@ Kernel space:
- Optional - Disable support for all x86 processes and syscalls (when using Linux kernel >= 6.7)
to reduce attack surface.
- Disable EFI persistent storage feature, preventing the kernel from writing crash logs and
other persistent data to the EFI variable store.
Direct memory access:
- Enable strict IOMMU translation to protect against some DMA attacks via the use