Linux kernel security tunables everyone should consider adopting
ID: 209c043e-e1e2-59f4-8467-fa06ce9e47e7
STIX ID: report--209c043e-e1e2-59f4-8467-fa06ce9e47e7
Feed Name: Cloudflare Blog
Cloudflare describes Linux kernel hardening practices to maintain system integrity: enforcing signed kernel modules with per-build ephemeral keys, disabling legacy kexec_load while using kexec_file_load with signature verification to retain crashdump support, enabling KASLR, restricting kernel pointer leaks (kptr_restrict, dmesg_restrict), and enforcing the Lockdown LSM (integrity by default). A demonstration shows how an unsigned module can flip SELinux to permissive on a stock Debian kernel, illustrating the need for these controls and emphasizing secure boot continuity and regular kernel updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
