projects
/
kconfig-hardened-check.git
/ blobdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
|
commitdiff
|
tree
raw
|
inline
| side by side
EFI mitigations can't be enabled if EFI is not set
[kconfig-hardened-check.git]
/
kconfig_hardened_check
/
config_files
/
kspp-recommendations
/
kspp-recommendations-x86-32.config
diff --git
a/kconfig_hardened_check/config_files/kspp-recommendations/kspp-recommendations-x86-32.config
b/kconfig_hardened_check/config_files/kspp-recommendations/kspp-recommendations-x86-32.config
index edca82b7414ee94eaa7b3b4d73896d6c70343482..a382f411912194929c2d93cd524cba4b753d6534 100644
(file)
--- a/
kconfig_hardened_check/config_files/kspp-recommendations/kspp-recommendations-x86-32.config
+++ b/
kconfig_hardened_check/config_files/kspp-recommendations/kspp-recommendations-x86-32.config
@@
-1,5
+1,5
@@
# CONFIGs
# CONFIGs
-# Linux/i386 5.4.0 Kernel Configuration
+# Linux/i386 5.
1
4.0 Kernel Configuration
# Report BUG() conditions and kill the offending process.
CONFIG_BUG=y
# Report BUG() conditions and kill the offending process.
CONFIG_BUG=y
@@
-171,6
+171,9
@@
CONFIG_DEFAULT_MMAP_MIN_ADDR=65536
# Randomize position of kernel.
CONFIG_RANDOMIZE_BASE=y
# Randomize position of kernel.
CONFIG_RANDOMIZE_BASE=y
+# Randomize kernel stack offset on syscall entry (since v5.13).
+CONFIG_RANDOMIZE_KSTACK_OFFSET_DEFAULT=y
+
# Enable Kernel Page Table Isolation to remove an entire class of cache timing side-channels.
CONFIG_PAGE_TABLE_ISOLATION=y
# Enable Kernel Page Table Isolation to remove an entire class of cache timing side-channels.
CONFIG_PAGE_TABLE_ISOLATION=y