File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -321,23 +321,32 @@ there are a few cases of partial or non-compliance due to technical limitations.
321321More than 30 kernel boot parameters and over 30 sysctl settings are fully aligned with
322322the KSPP's recommendations.
323323
324+ ** Partial compliance:**
325+
326+ 1 . Kernel boot parameter ` proc_mem.force_override=never `
327+
328+ Restrict processes from modifying their own memory mappings by completely disables use of
329+ ` /proc/PID/mem ` to write to protected pages. Can be enabled easily if required.
330+
331+ * [ security-misc pull request #332 ] ( https://github.com/Kicksecure/security-misc/pull/332 )
332+
324333** Non-compliance:**
325334
326- 1 . ` sysctl user.max_user_namespaces=0 `
335+ 2 . ` sysctl user.max_user_namespaces=0 `
327336
328337Disables user namespaces entirely. Not recommended due to the potential for widespread breakages.
329338
330339* [ security-misc pull request #263 ] ( https://github.com/Kicksecure/security-misc/pull/263 )
331340
332- 2 . ` sysctl fs.binfmt_misc.status=0 `
341+ 3 . ` sysctl fs.binfmt_misc.status=0 `
333342
334343Disables the registration of interpreters for miscellaneous binary formats. Currently not
335344feasible due to compatibility issues with Firefox.
336345
337346* [ security-misc pull request #249 ] ( https://github.com/Kicksecure/security-misc/pull/249 )
338347* [ security-misc issue #267 ] ( https://github.com/Kicksecure/security-misc/issues/267 )
339348
340- 3 . Kernel boot parameter ` hash_pointers=always `
349+ 4 . Kernel boot parameter ` hash_pointers=always `
341350
342351Force all exposed pointers to be hashed and must be used in combination with the already enabled
343352` slab_debug=FZ ` kernel boot parameter. Currently is not possible as requires Linux kernel >= 6.17.
Original file line number Diff line number Diff line change @@ -326,7 +326,8 @@ GRUB_CMDLINE_LINUX="$GRUB_CMDLINE_LINUX bdev_allow_write_mounted=0"
326326## https://github.com/a13xp0p0v/kernel-hardening-checker/pull/201
327327## https://github.com/Kicksecure/security-misc/issues/330
328328##
329- ## Using "proc_mem.force_override=never" provides superior protection by never allowing overrides.
329+ ## KSPP=partial
330+ ## KSPP sets the stricter kernel parameter proc_mem.force_override=never.
330331##
331332GRUB_CMDLINE_LINUX="$GRUB_CMDLINE_LINUX proc_mem.force_override=ptrace"
332333
You can’t perform that action at this time.
0 commit comments