[PATCH 25/27] Lock down /proc/kcore
From: dhowells@redhat.com (David Howells)
Date: 2017-10-23 14:57:01
Also in:
linux-efi, lkml
From: dhowells@redhat.com (David Howells)
Date: 2017-10-23 14:57:01
Also in:
linux-efi, lkml
James Morris [off-list ref] wrote:
I have to wonder, though, after everything is locked down, how easy will it be for new things to slip in which need to be included in the lockdown, but are not.
That's always a possibility, and short of reviewing every change, particularly in the drivers, I'm not sure how to prevent it. David -- To unsubscribe from this list: send the line "unsubscribe linux-security-module" in the body of a message to majordomo at vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html