Blame SOURCES/0290-set-kptr_restrict-1.patch
|
Brian Stinson |
2593d8 |
From cf1a9df1171273fc1ed3f977b5ec52aba27674bf Mon Sep 17 00:00:00 2001
|
|
Brian Stinson |
2593d8 |
From: David Tardon <dtardon@redhat.com>
|
|
Brian Stinson |
2593d8 |
Date: Tue, 3 Dec 2019 14:04:00 +0100
|
|
Brian Stinson |
2593d8 |
Subject: [PATCH] set kptr_restrict=1
|
|
Brian Stinson |
2593d8 |
|
|
Brian Stinson |
2593d8 |
Resolves: #1689346
|
|
Brian Stinson |
2593d8 |
---
|
|
Brian Stinson |
2593d8 |
sysctl.d/50-default.conf | 3 +++
|
|
Brian Stinson |
2593d8 |
1 file changed, 3 insertions(+)
|
|
Brian Stinson |
2593d8 |
|
|
Brian Stinson |
2593d8 |
diff --git a/sysctl.d/50-default.conf b/sysctl.d/50-default.conf
|
|
Brian Stinson |
2593d8 |
index e263cf0628..e0afc9c702 100644
|
|
Brian Stinson |
2593d8 |
--- a/sysctl.d/50-default.conf
|
|
Brian Stinson |
2593d8 |
+++ b/sysctl.d/50-default.conf
|
|
Brian Stinson |
2593d8 |
@@ -21,6 +21,9 @@ kernel.sysrq = 16
|
|
Brian Stinson |
2593d8 |
# Append the PID to the core filename
|
|
Brian Stinson |
2593d8 |
kernel.core_uses_pid = 1
|
|
Brian Stinson |
2593d8 |
|
|
Brian Stinson |
2593d8 |
+# https://bugzilla.redhat.com/show_bug.cgi?id=1689346
|
|
Brian Stinson |
2593d8 |
+kernel.kptr_restrict = 1
|
|
Brian Stinson |
2593d8 |
+
|
|
Brian Stinson |
2593d8 |
# Source route verification
|
|
Brian Stinson |
2593d8 |
net.ipv4.conf.all.rp_filter = 1
|
|
Brian Stinson |
2593d8 |
|