projects
/
kconfig-hardened-check.git
/ blobdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
|
commitdiff
|
tree
raw
|
inline
| side by side
Update the KSPP recommendations (https://github.com/KSPP/linux/issues/362)
[kconfig-hardened-check.git]
/
kernel_hardening_checker
/
config_files
/
kspp-recommendations
/
kspp-sysctl.txt
diff --git
a/kernel_hardening_checker/config_files/kspp-recommendations/kspp-sysctl.txt
b/kernel_hardening_checker/config_files/kspp-recommendations/kspp-sysctl.txt
index 9f99c6c501fd55082f66ac276b0453aa262fccb9..4c0c6eb09483ba0aa79929f2c759733d3863ad73 100644
(file)
--- a/
kernel_hardening_checker/config_files/kspp-recommendations/kspp-sysctl.txt
+++ b/
kernel_hardening_checker/config_files/kspp-recommendations/kspp-sysctl.txt
@@
-1,6
+1,7
@@
kernel.printk = 3 4 1 7
kernel.kptr_restrict = 2
kernel.dmesg_restrict = 1
kernel.printk = 3 4 1 7
kernel.kptr_restrict = 2
kernel.dmesg_restrict = 1
+kernel.modules_disabled = 1
kernel.perf_event_paranoid = 3
kernel.kexec_load_disabled = 1
kernel.randomize_va_space = 2
kernel.perf_event_paranoid = 3
kernel.kexec_load_disabled = 1
kernel.randomize_va_space = 2
@@
-9,6
+10,8
@@
user.max_user_namespaces = 0
dev.tty.ldisc_autoload = 0
dev.tty.legacy_tiocsti = 0
kernel.unprivileged_bpf_disabled = 1
dev.tty.ldisc_autoload = 0
dev.tty.legacy_tiocsti = 0
kernel.unprivileged_bpf_disabled = 1
+kernel.warn_limit = 1
+kernel.oops_limit = 1
net.core.bpf_jit_harden = 2
vm.unprivileged_userfaultfd = 0
fs.protected_symlinks = 1
net.core.bpf_jit_harden = 2
vm.unprivileged_userfaultfd = 0
fs.protected_symlinks = 1