Skip to content
Snippets Groups Projects
  1. Sep 24, 2023
  2. Mar 26, 2023
  3. Aug 29, 2022
  4. Aug 23, 2022
  5. Jun 08, 2022
  6. Feb 14, 2022
    • Evangelos Foutras's avatar
      hardening: use default ptrace scope on buildservers · f6cbd3f8
      Evangelos Foutras authored
      Making 'kernel.yama.ptrace_scope' more strict by setting it to '2'
      causes failures in elfutils' test suite. While tentatively helpful
      on other servers, it seems kind of unnecessary for a build server.
      
      Fixes: #424 (to be reopened though, if more restrictions are found)
      f6cbd3f8
  7. Sep 15, 2020
    • Levente Polyak's avatar
      kernel: further default sysctl hardening · b2ba1877
      Levente Polyak authored
      - unprivileged bpf: we do not need this on our infra, we can assume
        bpf() calls will happen with CAP_SYS_ADMIN if required.
      
      - unprivileged userns: we do not need this on our infra for none of
        our services or similar. Reduce attack surface by a huge margin
        including most recent CVE-2020-14386.
      
      - kptr restrict: we already check for CAP_SYSLOG and real ids but we
        really do not require any specific kernel pointers to be logged.
        Settings this to 2 instead to blank out all kernel pointers to
        protect against info leak.
      
      - kexec: disable kexec as we do never want to kexec our running servers
        into something else. Settings this sysctl disables kexec even if its
        compiled into the kernel.
      
      - bpf jit harden: harden BPF JIT compiler to mitigate JIT spraying for
        the sacrifices off a bit performance for all users including
        privileged.
      Verified
      b2ba1877
  8. Aug 27, 2020
  9. Feb 13, 2020
  10. Dec 22, 2019
  11. May 07, 2019
Loading