Skip to content

Backporting security features to LTS kernels #30

@madaidan

Description

@madaidan

Stable kernels have various security features that LTS kernels don't have such as lockdown, SafeSetID, page allocator freelist randomization, init_on_alloc etc. I think linux-hardened should backport/reimplement those security features in LTS kernels.

I can contribute many of these myself if you're interested. I've created some patches already.

This would be especially useful for Whonix's hardened-kernel as we're using LTS kernels for greater stability and less attack surface.

Metadata

Metadata

Assignees

No one assigned

    Labels

    questionFurther information is requested

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions