[d-kernel] [PATCH 5.10.y] config: CONFIG_RANDOMIZE_BASE=y

dutyrok на altlinux.org dutyrok на altlinux.org
Чт Апр 11 14:03:53 MSK 2024


From: Alexandr Shashkin <dutyrok на altlinux.org>

Enable kernel address space layout randomization to prevent guest
security exploits based on the location of kernel objects.

Signed-off-by: Alexandr Shashkin <dutyrok на altlinux.org>
---
 config | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/config b/config
index 9bd005564e56..e5917be74550 100644
--- a/config
+++ b/config
@@ -473,7 +473,7 @@ CONFIG_CRASH_DUMP=y
 # CONFIG_KEXEC_JUMP is not set
 CONFIG_PHYSICAL_START=0x1000000
 CONFIG_RELOCATABLE=y
-# CONFIG_RANDOMIZE_BASE is not set
+CONFIG_RANDOMIZE_BASE=y
 CONFIG_PHYSICAL_ALIGN=0x1000000
 CONFIG_HOTPLUG_CPU=y
 # CONFIG_BOOTPARAM_HOTPLUG_CPU0 is not set
-- 
2.33.8



Подробная информация о списке рассылки devel-kernel