mirror of
https://github.com/ryan4yin/nix-config.git
synced 2026-05-14 20:01:00 +02:00
fix: mitigate Dirty Frag LPE vulnerabilities
This commit is contained in:
20
modules/nixos/base/kernel-hardening.nix
Normal file
20
modules/nixos/base/kernel-hardening.nix
Normal file
@@ -0,0 +1,20 @@
|
||||
{
|
||||
config,
|
||||
lib,
|
||||
pkgs,
|
||||
...
|
||||
}:
|
||||
{
|
||||
# Kernel module blacklisting to mitigate Dirty Frag LPE (Local Privilege Escalation) vulnerabilities.
|
||||
boot.blacklistedKernelModules = [
|
||||
"esp4"
|
||||
"esp6"
|
||||
"rxrpc"
|
||||
];
|
||||
|
||||
boot.extraModprobeConfig = ''
|
||||
install esp4 ${pkgs.coreutils}/bin/false
|
||||
install esp6 ${pkgs.coreutils}/bin/false
|
||||
install rxrpc ${pkgs.coreutils}/bin/false
|
||||
'';
|
||||
}
|
||||
Reference in New Issue
Block a user