forked from GrapheneOS/linux-hardened
-
Notifications
You must be signed in to change notification settings - Fork 57
Open
Labels
questionFurther information is requestedFurther information is requested
Description
Stable kernels have various security features that LTS kernels don't have such as lockdown, SafeSetID, page allocator freelist randomization, init_on_alloc etc. I think linux-hardened should backport/reimplement those security features in LTS kernels.
I can contribute many of these myself if you're interested. I've created some patches already.
This would be especially useful for Whonix's hardened-kernel as we're using LTS kernels for greater stability and less attack surface.
Metadata
Metadata
Assignees
Labels
questionFurther information is requestedFurther information is requested