It appears you have not yet registered with our community. To register please click here...

 
Go Back [M] > Madshrimps > WebNews
Torvalds approves kernel lock-down Torvalds approves kernel lock-down
FAQ Members List Calendar Search Today's Posts Mark Forums Read


Torvalds approves kernel lock-down
Reply
 
Thread Tools
Old 30th September 2019, 14:53   #1
[M] Reviewer
 
Stefan Mileschin's Avatar
 
Join Date: May 2010
Location: Romania
Posts: 148,618
Stefan Mileschin Freshly Registered
Default Torvalds approves kernel lock-down

Thou shalt not change the kernel code

Over the weekend, IT's Mr Sweary Linus Torvalds approved a new security feature for the Linux kernel, named 'lockdown'.

The new feature will ship as a LSM (Linux Security Module) in the soon to be released Linux kernel 5.4 branches, where it will be turned off by default. It has to be optional because it could break existing systems.

The new feature's primary function will be to strengthen the divide between userland processes and kernel code by preventing even the root account from interacting with kernel code -- something that it's been able to do, by design, until now.

When enabled, the new "lockdown" feature will restrict some kernel functionality, even for the root user, making it harder for compromised root accounts to compromise the rest of the OS.

Torvalds said: "When enabled, various pieces of kernel functionality are restricted. This includes restricting access to kernel features that may allow arbitrary code execution via code supplied by userland processes; blocking processes from writing or reading /dev/mem and /dev/kmem memory; block access to opening /dev/port to prevent raw port access; enforcing kernel module signatures; and many more others."

https://fudzilla.com/news/pc-hardwar...rnal-lock-down
Stefan Mileschin is offline   Reply With Quote
Reply


Similar Threads
Thread Thread Starter Forum Replies Last Post
Linus Torvalds is back in charge Stefan Mileschin WebNews 0 24th October 2018 12:31
Torvalds says Intel needs to admit it has a problem Stefan Mileschin WebNews 0 8th January 2018 18:22
Torvalds rants about security Stefan Mileschin WebNews 0 24th November 2017 18:16
Torvalds grrs at grsecurity Stefan Mileschin WebNews 0 26th June 2017 13:32
Torvalds gives the thumbs up to SteamOS Stefan Mileschin WebNews 0 25th October 2013 07:26
Torvalds furious at latest Linux kernel Stefan Mileschin WebNews 0 11th June 2013 07:06
Torvalds upset that his kernel is too big Stefan Mileschin WebNews 0 18th July 2012 07:48
Nvidia to have a word with Torvalds Stefan Mileschin WebNews 0 22nd June 2012 07:23
Linus Torvalds slams Nvidia Stefan Mileschin WebNews 0 18th June 2012 10:41
Linus Torvalds wrestles with Gnome 3 Stefan Mileschin WebNews 0 13th June 2012 06:32

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 15:46.


Powered by vBulletin® - Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO