commit | 02e935bf5b34edcc4cb0dc532dd0e1a1bfb33b51 | [log] [tgz] |
---|---|---|
author | David Howells <dhowells@redhat.com> | Mon Aug 19 17:17:57 2019 -0700 |
committer | James Morris <jmorris@namei.org> | Mon Aug 19 21:54:16 2019 -0700 |
tree | d1029d3f5dccd6dbba74b1d0b445fa2b5ee4ffb4 | |
parent | 906357f77a077508d160e729f917c5f0a4304f25 [diff] |
lockdown: Lock down /proc/kcore Disallow access to /proc/kcore when the kernel is locked down to prevent access to cryptographic data. This is limited to lockdown confidentiality mode and is still permitted in integrity mode. Signed-off-by: David Howells <dhowells@redhat.com> Signed-off-by: Matthew Garrett <mjg59@google.com> Reviewed-by: Kees Cook <keescook@chromium.org> Signed-off-by: James Morris <jmorris@namei.org>