mirror of
https://github.com/Kicksecure/security-misc.git
synced 2025-01-13 01:59:27 -05:00
Merge remote-tracking branch 'origin/master'
This commit is contained in:
commit
e6e7886a6e
@ -15,7 +15,8 @@ prereqs)
|
|||||||
;;
|
;;
|
||||||
esac
|
esac
|
||||||
|
|
||||||
sysctl -p ${rootmnt}/etc/sysctl.conf >/dev/null
|
sysctl -p ${rootmnt}/etc/sysctl.conf >/dev/null 2>${rootmnt}/var/log/sysctl-initramfs-error.log
|
||||||
sysctl -p ${rootmnt}/etc/sysctl.d/*.conf >/dev/null
|
sysctl -p ${rootmnt}/etc/sysctl.d/*.conf >/dev/null 2>>${rootmnt}/var/log/sysctl-initramfs-error.log
|
||||||
|
grep -v "unprivileged_userfaultfd" /var/log/sysctl-initramfs-error.log
|
||||||
|
|
||||||
true
|
true
|
||||||
|
@ -134,10 +134,8 @@ kernel.sysrq=132
|
|||||||
## https://lkml.org/lkml/2019/4/15/890
|
## https://lkml.org/lkml/2019/4/15/890
|
||||||
dev.tty.ldisc_autoload=0
|
dev.tty.ldisc_autoload=0
|
||||||
|
|
||||||
## Disable for now.
|
|
||||||
## https://forums.whonix.org/t/kernel-hardening/7296/406
|
|
||||||
## Restrict the userfaultfd() syscall to root as it can make heap sprays
|
## Restrict the userfaultfd() syscall to root as it can make heap sprays
|
||||||
## easier.
|
## easier.
|
||||||
##
|
##
|
||||||
## https://duasynt.com/blog/linux-kernel-heap-spray
|
## https://duasynt.com/blog/linux-kernel-heap-spray
|
||||||
#vm.unprivileged_userfaultfd=0
|
vm.unprivileged_userfaultfd=0
|
||||||
|
Loading…
Reference in New Issue
Block a user