
Инструмент для проверки параметров усиления безопасности ядра Linux
(ранее kconfig-hardened-check)
Существует множество опций для усиления безопасности ядра Linux. Многие из них не включены по умолчанию в основных дистрибутивах. Нам приходится включать эти опции самостоятельно, чтобы сделать наши системы более безопасными.
Но никому не нравится проверять конфиги вручную. Так пусть компьютеры делают свою работу!
kernel-hardening-checker (ранее kconfig-hardened-check) — это инструмент для проверки опций усиления безопасности ядра Linux.
Лицензия: GPL-3.0.
kernel-hardening-checker поддерживает проверку:
Поддерживаемые архитектуры:
Рекомендации по усилению безопасности основаны на:
Я также создал [Карту защиты ядра Linux][4], которая представляет собой графическое изображение связей между функциями усиления безопасности и соответствующими классами уязвимостей или техниками эксплуатации.
Пожалуйста, учтите, что изменение параметров безопасности ядра Linux может повлиять на производительность системы и функциональность пользовательского программного обеспечения. Поэтому при установке этих параметров учитывайте модель угроз вашей информационной системы на базе Linux и тщательно тестируйте её типовую рабочую нагрузку.
Есть несколько вариантов:
Вы можете установить пакет из этого Git-репозитория с помощью pip:
python3 -m pip install git+https://github.com/a13xp0p0v/kernel-hardening-checker
Если вы получили ошибку из-за внешне управляемого окружения, создайте виртуальное окружение с помощью python3 -m venv.
Вы можете установить пакет kernel-hardening-checker через менеджер пакетов в некоторых дистрибутивах GNU/Linux. См. https://repology.org/project/kernel-hardening-checker/versions
Кроме того, вы можете просто запустить ./bin/kernel-hardening-checker из клонированного репозитория без установки.
$ ./bin/kernel-hardening-checker -h usage: kernel-hardening-checker [-h] [--version] [-m {verbose,json,show_ok,show_fail}] [-a] [-c CONFIG] [-v KERNEL_VERSION] [-l CMDLINE] [-s SYSCTL] [-p {X86_64,X86_32,ARM64,ARM,RISCV}] [-g {X86_64,X86_32,ARM64,ARM,RISCV}]
A tool for checking the security hardening options of the Linux kernel
options: -h, --help show this help message and exit --version show program's version number and exit -m, --mode {verbose,json,show_ok,show_fail} select a special output mode instead of the default one -a, --autodetect autodetect and check the security hardening options of the running kernel -c, --config CONFIG check the security hardening options in a Kconfig file (also supports *.gz files) -v, --kernel-version KERNEL_VERSION extract the kernel version from a version file (such as /proc/version) instead of using a Kconfig file -l, --cmdline CMDLINE check the security hardening options in a kernel command line file (such as /proc/cmdline) -s, --sysctl SYSCTL check the security hardening options in a sysctl output file (the result of "sudo sysctl -a > file") -p, --print {X86_64,X86_32,ARM64,ARM,RISCV} print security hardening recommendations for the selected architecture -g, --generate {X86_64,X86_32,ARM64,ARM,RISCV} generate a Kconfig fragment containing the security hardening options for the selected architecture
## Режимы вывода
- аргумент без `-m` для режима вывода по умолчанию (см. пример ниже)
- `-m verbose` для вывода дополнительной информации:
- параметры конфигурации без соответствующей проверки
- внутреннее устройство сложных проверок с AND/OR, например:
```
-------------------------------------------------------------------------------------------
<<< OR >>>
CONFIG_STRICT_DEVMEM |kconfig|cut_attack_surface|defconfig | y
CONFIG_DEVMEM |kconfig|cut_attack_surface| kspp | is not set
-------------------------------------------------------------------------------------------
```
- `-m json` для вывода результатов в формате JSON (для совмещения `kernel-hardening-checker` с другими инструментами)
- `-m show_ok` для отображения только успешных проверок
- `-m show_fail` для отображения только неудачных проверок
## Пример вывода```
$ ./bin/kernel-hardening-checker -a
[+] Going to autodetect and check the security hardening options of the running kernel
[+] Detected version of the running kernel: (6, 11, 0)
[+] Detected kconfig file of the running kernel: /boot/config-6.11.0-1007-oem
[+] Detected cmdline parameters of the running kernel: /proc/cmdline
[+] Saved sysctls to a temporary file /tmp/sysctl-at_0n9si
[+] Detected architecture: X86_64
[+] Detected compiler: GCC 130200
[!] WARNING: sysctl options available for root are not found in /tmp/sysctl-at_0n9si, try checking the output of "sudo sysctl -a"
=========================================================================================================================
option_name | type | reason | decision |desired_val | check_result
=========================================================================================================================
CONFIG_BUG |kconfig| self_protection |defconfig | y | OK
CONFIG_SLUB_DEBUG |kconfig| self_protection |defconfig | y | OK
CONFIG_THREAD_INFO_IN_TASK |kconfig| self_protection |defconfig | y | OK
CONFIG_IOMMU_DEFAULT_PASSTHROUGH |kconfig| self_protection |defconfig | is not set | OK
CONFIG_IOMMU_SUPPORT |kconfig| self_protection |defconfig | y | OK
CONFIG_STACKPROTECTOR |kconfig| self_protection |defconfig | y | OK
CONFIG_STACKPROTECTOR_STRONG |kconfig| self_protection |defconfig | y | OK
CONFIG_STRICT_KERNEL_RWX |kconfig| self_protection |defconfig | y | OK
CONFIG_STRICT_MODULE_RWX |kconfig| self_protection |defconfig | y | OK
CONFIG_REFCOUNT_FULL |kconfig| self_protection |defconfig | y | OK: version >= (5, 4, 208)
CONFIG_INIT_STACK_ALL_ZERO |kconfig| self_protection |defconfig | y | OK
CONFIG_CPU_MITIGATIONS |kconfig| self_protection |defconfig | y | OK
CONFIG_RANDOMIZE_BASE |kconfig| self_protection |defconfig | y | OK
CONFIG_VMAP_STACK |kconfig| self_protection |defconfig | y | OK
CONFIG_LSM_MMAP_MIN_ADDR |kconfig| self_protection |defconfig | 65536 | FAIL: "0"
CONFIG_DEBUG_WX |kconfig| self_protection |defconfig | y | OK
CONFIG_WERROR |kconfig| self_protection |defconfig | y | FAIL: "is not set"
CONFIG_X86_MCE |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_SPECTRE_V1 |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_SPECTRE_V2 |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_SSB |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MICROCODE |kconfig| self_protection |defconfig | y | OK
CONFIG_MICROCODE_INTEL |kconfig| self_protection |defconfig | y | OK: CONFIG_MICROCODE is "y"
CONFIG_MICROCODE_AMD |kconfig| self_protection |defconfig | y | OK: CONFIG_MICROCODE is "y"
CONFIG_X86_SMAP |kconfig| self_protection |defconfig | y | OK: version >= (5, 19, 0)
CONFIG_X86_UMIP |kconfig| self_protection |defconfig | y | OK
CONFIG_X86_MCE_INTEL |kconfig| self_protection |defconfig | y | OK
CONFIG_X86_MCE_AMD |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_RETPOLINE |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_GDS |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_RFDS |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_SPECTRE_BHI |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_MDS |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_TAA |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_MMIO_STALE_DATA |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_L1TF |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_RETBLEED |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_SRBDS |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_TSA |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_MITIGATION_VMSCAPE |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_RANDOMIZE_MEMORY |kconfig| self_protection |defconfig | y | OK
CONFIG_X86_KERNEL_IBT |kconfig| self_protection |defconfig | y | FAIL: "is not set"
CONFIG_MITIGATION_RETHUNK |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_PAGE_TABLE_ISOLATION|kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_UNRET_ENTRY |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_CALL_DEPTH_TRACKING |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_IBPB_ENTRY |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_IBRS_ENTRY |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_SRSO |kconfig| self_protection |defconfig | y | OK
CONFIG_MITIGATION_ITS |kconfig| self_protection |defconfig | y | FAIL: is not found
CONFIG_INTEL_IOMMU |kconfig| self_protection |defconfig | y | OK
CONFIG_AMD_IOMMU |kconfig| self_protection |defconfig | y | OK
CONFIG_RANDOM_KMALLOC_CACHES |kconfig| self_protection | kspp | y | OK
CONFIG_SLAB_MERGE_DEFAULT |kconfig| self_protection | kspp | is not set | FAIL: "y"
CONFIG_BUG_ON_DATA_CORRUPTION |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_SLAB_FREELIST_HARDENED |kconfig| self_protection | kspp | y | OK
CONFIG_SLAB_FREELIST_RANDOM |kconfig| self_protection | kspp | y | OK
CONFIG_SHUFFLE_PAGE_ALLOCATOR |kconfig| self_protection | kspp | y | OK
CONFIG_FORTIFY_SOURCE |kconfig| self_protection | kspp | y | OK
CONFIG_DEBUG_VIRTUAL |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_INIT_ON_ALLOC_DEFAULT_ON |kconfig| self_protection | kspp | y | OK
CONFIG_STATIC_USERMODEHELPER |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_SECURITY_LOCKDOWN_LSM |kconfig| self_protection | kspp | y | OK
CONFIG_LSM |kconfig| self_protection | kspp | *lockdown* | OK: in "landlock,lockdown,yama,integrity,apparmor"
CONFIG_SECURITY_LOCKDOWN_LSM_EARLY |kconfig| self_protection | kspp | y | OK
CONFIG_LOCK_DOWN_KERNEL_FORCE_CONFIDENTIALITY|kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_DEBUG_SG |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_ZERO_CALL_USED_REGS |kconfig| self_protection | kspp | y | OK
CONFIG_DEBUG_CREDENTIALS |kconfig| self_protection | kspp | y | OK: version >= (6, 6, 8)
CONFIG_DEBUG_NOTIFIERS |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_KFENCE |kconfig| self_protection | kspp | y | OK
CONFIG_KFENCE_SAMPLE_INTERVAL |kconfig| self_protection | kspp | 100 | FAIL: "0"
CONFIG_RANDSTRUCT_FULL |kconfig| self_protection | kspp | y | FAIL: is not found
CONFIG_HARDENED_USERCOPY |kconfig| self_protection | kspp | y | OK
CONFIG_HARDENED_USERCOPY_DEFAULT_ON |kconfig| self_protection | kspp | y | FAIL: is not found
CONFIG_HARDENED_USERCOPY_FALLBACK |kconfig| self_protection | kspp | is not set | OK: is not found
CONFIG_HARDENED_USERCOPY_PAGESPAN |kconfig| self_protection | kspp | is not set | OK: is not found
CONFIG_GCC_PLUGIN_LATENT_ENTROPY |kconfig| self_protection | kspp | y | FAIL: is not found
CONFIG_MODULE_SIG |kconfig| self_protection | kspp | y | OK
CONFIG_MODULE_SIG_ALL |kconfig| self_protection | kspp | y | OK
CONFIG_MODULE_SIG_SHA512 |kconfig| self_protection | kspp | y | OK
CONFIG_MODULE_SIG_FORCE |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_INIT_ON_FREE_DEFAULT_ON |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_EFI_DISABLE_PCI_DMA |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_RESET_ATTACK_MITIGATION |kconfig| self_protection | kspp | y | OK
CONFIG_UBSAN_BOUNDS |kconfig| self_protection | kspp | y | OK
CONFIG_UBSAN_LOCAL_BOUNDS |kconfig| self_protection | kspp | y | OK: CONFIG_UBSAN_BOUNDS is "y"
CONFIG_UBSAN_TRAP |kconfig| self_protection | kspp | y | FAIL: CONFIG_UBSAN_ENUM is not "is not set"
CONFIG_UBSAN_SANITIZE_ALL |kconfig| self_protection | kspp | y | OK: CONFIG_UBSAN_BOUNDS is "y"
CONFIG_SCHED_STACK_END_CHECK |kconfig| self_protection | kspp | y | OK
CONFIG_KSTACK_ERASE |kconfig| self_protection | kspp | y | FAIL: is not found
CONFIG_KSTACK_ERASE_METRICS |kconfig| self_protection | kspp | is not set | FAIL: CONFIG_KSTACK_ERASE is not "y"
CONFIG_KSTACK_ERASE_RUNTIME_DISABLE |kconfig| self_protection | kspp | is not set | FAIL: CONFIG_KSTACK_ERASE is not "y"
CONFIG_SCHED_CORE |kconfig| self_protection | kspp | y | OK
CONFIG_LIST_HARDENED |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_RANDOMIZE_KSTACK_OFFSET_DEFAULT|kconfig| self_protection | kspp | y | OK
CONFIG_PAGE_TABLE_CHECK |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_PAGE_TABLE_CHECK_ENFORCED |kconfig| self_protection | kspp | y | FAIL: is not found
CONFIG_DEFAULT_MMAP_MIN_ADDR |kconfig| self_protection | kspp | 65536 | OK
CONFIG_HW_RANDOM_TPM |kconfig| self_protection | kspp | y | OK
CONFIG_CFI_CLANG |kconfig| self_protection | kspp | y | FAIL: CONFIG_CC_IS_CLANG is not "y"
CONFIG_CFI_PERMISSIVE |kconfig| self_protection | kspp | is not set | FAIL: CONFIG_CC_IS_CLANG is not "y"
CONFIG_IOMMU_DEFAULT_DMA_STRICT |kconfig| self_protection | kspp | y | FAIL: "is not set"
CONFIG_INTEL_IOMMU_DEFAULT_ON |kconfig| self_protection | kspp | y | OK
CONFIG_CFI_AUTO_DEFAULT |kconfig| self_protection | kspp | is not set | FAIL: CONFIG_CFI_AUTO_DEFAULT is not present
CONFIG_MITIGATION_SLS |kconfig| self_protection | kspp | y | OK
CONFIG_INTEL_IOMMU_SVM |kconfig| self_protection | kspp | y | OK
CONFIG_AMD_IOMMU_V2 |kconfig| self_protection | kspp | y | OK: version >= (6, 7, 0)
CONFIG_SECURITY |kconfig| security_policy |defconfig | y | OK
CONFIG_SECURITY_YAMA |kconfig| security_policy | kspp | y | OK
CONFIG_LSM |kconfig| security_policy | kspp | *yama* | OK: in "landlock,lockdown,yama,integrity,apparmor"
CONFIG_SECURITY_LANDLOCK |kconfig| security_policy | kspp | y | OK
CONFIG_LSM |kconfig| security_policy | kspp | *landlock* | OK: in "landlock,lockdown,yama,integrity,apparmor"
CONFIG_SECURITY_SELINUX_DISABLE |kconfig| security_policy | kspp | is not set | OK: is not found
CONFIG_SECURITY_SELINUX_BOOTPARAM |kconfig| security_policy | kspp | is not set | FAIL: "y"
CONFIG_SECURITY_SELINUX_DEVELOP |kconfig| security_policy | kspp | is not set | FAIL: "y"
CONFIG_SECURITY_WRITABLE_HOOKS |kconfig| security_policy | kspp | is not set | OK: is not found
CONFIG_SECURITY_SELINUX_DEBUG |kconfig| security_policy | kspp | is not set | OK
CONFIG_SECURITY_SELINUX |kconfig| security_policy |a13xp0p0v | y | OK
CONFIG_LSM |kconfig| security_policy |a13xp0p0v | *selinux* | OK: "apparmor" is in CONFIG_LSM
CONFIG_SECCOMP |kconfig|cut_attack_surface|defconfig | y | OK
CONFIG_SECCOMP_FILTER |kconfig|cut_attack_surface|defconfig | y | OK
CONFIG_BPF_UNPRIV_DEFAULT_OFF |kconfig|cut_attack_surface|defconfig | y | OK
CONFIG_STRICT_DEVMEM |kconfig|cut_attack_surface|defconfig | y | OK
CONFIG_X86_INTEL_TSX_MODE_OFF |kconfig|cut_attack_surface|defconfig | y | OK
CONFIG_SECURITY_DMESG_RESTRICT |kconfig|cut_attack_surface| kspp | y | OK
CONFIG_ACPI_CUSTOM_METHOD |kconfig|cut_attack_surface| kspp | is not set | OK: is not found
CONFIG_COMPAT_BRK |kconfig|cut_attack_surface| kspp | is not set | OK
CONFIG_DEVKMEM |kconfig|cut_attack_surface| kspp | is not set | OK: is not found
CONFIG_BINFMT_MISC |kconfig|cut_attack_surface| kspp | is not set | FAIL: "m"
CONFIG_INET_DIAG |kconfig|cut_attack_surface| kspp | is not set | FAIL: "m"
CONFIG_KEXEC |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_PROC_KCORE |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_LEGACY_PTYS |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_HIBERNATION |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_COMPAT |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_IA32_EMULATION |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_X86_X32 |kconfig|cut_attack_surface| kspp | is not set | OK: is not found
CONFIG_X86_X32_ABI |kconfig|cut_attack_surface| kspp | is not set | OK
CONFIG_MODIFY_LDT_SYSCALL |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_OABI_COMPAT |kconfig|cut_attack_surface| kspp | is not set | OK: is not found
CONFIG_X86_MSR |kconfig|cut_attack_surface| kspp | is not set | FAIL: "m"
CONFIG_LEGACY_TIOCSTI |kconfig|cut_attack_surface| kspp | is not set | OK
CONFIG_MODULE_FORCE_LOAD |kconfig|cut_attack_surface| kspp | is not set | OK
CONFIG_M486 |kconfig|cut_attack_surface| kspp | is not set | OK: is not found
CONFIG_MODULES |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_DEVMEM |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_IO_STRICT_DEVMEM |kconfig|cut_attack_surface| kspp | y | FAIL: "is not set"
CONFIG_LDISC_AUTOLOAD |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_X86_VSYSCALL_EMULATION |kconfig|cut_attack_surface| kspp | is not set | FAIL: "y"
CONFIG_COMPAT_VDSO |kconfig|cut_attack_surface| kspp | is not set | OK
CONFIG_DRM_LEGACY |kconfig|cut_attack_surface|maintainer| is not set | OK: is not found
CONFIG_FB |kconfig|cut_attack_surface|maintainer| is not set | FAIL: "y"
CONFIG_VT |kconfig|cut_attack_surface|maintainer| is not set | FAIL: "y"
CONFIG_BLK_DEV_FD |kconfig|cut_attack_surface|maintainer| is not set | FAIL: "m"
CONFIG_BLK_DEV_FD_RAWCMD |kconfig|cut_attack_surface|maintainer| is not set | OK
CONFIG_NOUVEAU_LEGACY_CTX_SUPPORT |kconfig|cut_attack_surface|maintainer| is not set | OK: is not found
CONFIG_N_GSM |kconfig|cut_attack_surface|maintainer| is not set | FAIL: "m"
CONFIG_ZSMALLOC_STAT |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_DEBUG_KMEMLEAK |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_BINFMT_AOUT |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_KPROBE_EVENTS |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_UPROBE_EVENTS |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_GENERIC_TRACER |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_FUNCTION_TRACER |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_STACK_TRACER |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_HIST_TRIGGERS |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_BLK_DEV_IO_TRACE |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_PROC_VMCORE |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_PROC_PAGE_MONITOR |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_USELIB |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_CHECKPOINT_RESTORE |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_USERFAULTFD |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_HWPOISON_INJECT |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_MEM_SOFT_DIRTY |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_DEVPORT |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_DEBUG_FS |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_NOTIFIER_ERROR_INJECTION |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_FAIL_FUTEX |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_PUNIT_ATOM_DEBUG |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_ACPI_CONFIGFS |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_EDAC_DEBUG |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_DRM_I915_DEBUG |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_DVB_C8SECTPFE |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_MTD_SLRAM |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_MTD_PHRAM |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_IO_URING |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_KCMP |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_RSEQ |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_LATENCYTOP |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_KCOV |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_PROVIDE_OHCI1394_DMA_INIT |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_SUNRPC_DEBUG |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_X86_16BIT |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_BLK_DEV_UBLK |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_SMB_SERVER |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_XFS_ONLINE_SCRUB_STATS |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_CACHESTAT_SYSCALL |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_PREEMPTIRQ_TRACEPOINTS |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_ENABLE_DEFAULT_TRACERS |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_PROVE_LOCKING |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_TEST_DEBUG_VIRTUAL |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_MPTCP |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_TLS |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_TIPC |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_IP_SCTP |kconfig|cut_attack_surface| grsec | is not set | FAIL: "m"
CONFIG_KGDB |kconfig|cut_attack_surface| grsec | is not set | FAIL: "y"
CONFIG_PTDUMP_DEBUGFS |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_X86_PTDUMP |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_DEBUG_CLOSURES |kconfig|cut_attack_surface| grsec | is not set | OK
CONFIG_BCACHE_CLOSURES_DEBUG |kconfig|cut_attack_surface| grsec | is not set | OK: is not found
CONFIG_STAGING |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_KSM |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_KALLSYMS |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_KEXEC_FILE |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_CRASH_DUMP |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_USER_NS |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_X86_CPUID |kconfig|cut_attack_surface| clipos | is not set | FAIL: "m"
CONFIG_X86_IOPL_IOPERM |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_ACPI_TABLE_UPGRADE |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_EFI_CUSTOM_SSDT_OVERLAYS |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_AIO |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_MAGIC_SYSRQ |kconfig|cut_attack_surface| clipos | is not set | FAIL: "y"
CONFIG_MAGIC_SYSRQ_SERIAL |kconfig|cut_attack_surface|grapheneos| is not set | FAIL: "y"
CONFIG_EFI_TEST |kconfig|cut_attack_surface| lockdown | is not set | FAIL: "m"
CONFIG_MMIOTRACE_TEST |kconfig|cut_attack_surface| lockdown | is not set | OK
CONFIG_KPROBES |kconfig|cut_attack_surface| lockdown | is not set | FAIL: "y"
CONFIG_BPF_SYSCALL |kconfig|cut_attack_surface| lockdown | is not set | FAIL: "y"
CONFIG_MMIOTRACE |kconfig|cut_attack_surface|a13xp0p0v | is not set | FAIL: "y"
CONFIG_LIVEPATCH |kconfig|cut_attack_surface|a13xp0p0v | is not set | FAIL: "y"
CONFIG_IP_DCCP |kconfig|cut_attack_surface|a13xp0p0v | is not set | FAIL: "m"
CONFIG_FTRACE |kconfig|cut_attack_surface|a13xp0p0v | is not set | FAIL: "y"
CONFIG_VIDEO_VIVID |kconfig|cut_attack_surface|a13xp0p0v | is not set | FAIL: "m"
CONFIG_INPUT_EVBUG |kconfig|cut_attack_surface|a13xp0p0v | is not set | FAIL: "m"
CONFIG_CORESIGHT |kconfig|cut_attack_surface|a13xp0p0v | is not set | OK: is not found
CONFIG_XFS_SUPPORT_V4 |kconfig|cut_attack_surface|a13xp0p0v | is not set | FAIL: "y"
CONFIG_BLK_DEV_WRITE_MOUNTED |kconfig|cut_attack_surface|a13xp0p0v | is not set | FAIL: "y"
CONFIG_FAULT_INJECTION |kconfig|cut_attack_surface|a13xp0p0v | is not set | OK
CONFIG_ARM_PTDUMP_DEBUGFS |kconfig|cut_attack_surface|a13xp0p0v | is not set | OK: is not found
CONFIG_ARM_PTDUMP |kconfig|cut_attack_surface|a13xp0p0v | is not set | OK: is not found
CONFIG_SECCOMP_CACHE_DEBUG |kconfig|cut_attack_surface|a13xp0p0v | is not set | OK
CONFIG_CRASH_DM_CRYPT |kconfig|cut_attack_surface|a13xp0p0v | is not set | OK: is not found
CONFIG_LKDTM |kconfig|cut_attack_surface|a13xp0p0v | is not set | OK
CONFIG_TRIM_UNUSED_KSYMS |kconfig|cut_attack_surface|a13xp0p0v | y | FAIL: "is not set"
CONFIG_SYN_COOKIES |kconfig| network_security |defconfig | y | OK
CONFIG_COREDUMP |kconfig| harden_userspace | clipos | is not set | FAIL: "y"
CONFIG_PROC_MEM_NO_FORCE |kconfig| harden_userspace |a13xp0p0v | y | FAIL: is not found
CONFIG_ARCH_MMAP_RND_BITS |kconfig| harden_userspace |a13xp0p0v | 32 | OK
CONFIG_ARCH_MMAP_RND_COMPAT_BITS |kconfig| harden_userspace |a13xp0p0v | 16 | OK
CONFIG_X86_USER_SHADOW_STACK |kconfig| harden_userspace | kspp | y | OK
nokaslr |cmdline| self_protection |defconfig | is not set | OK: is not found
no_hash_pointers |cmdline| self_protection |defconfig | is not set | OK: is not found
nosmep |cmdline| self_protection |defconfig | is not set | OK: is not found
nosmap |cmdline| self_protection |defconfig | is not set | OK: is not found
dis_ucode_ldr |cmdline| self_protection |defconfig | is not set | OK: is not found
setcpuid |cmdline| self_protection |defconfig | is not set | OK: is not found
clearcpuid |cmdline| self_protection |defconfig | is not set | OK: is not found
nopti |cmdline| self_protection |defconfig | is not set | OK: is not found
nospec_store_bypass_disable |cmdline| self_protection |defconfig | is not set | OK: is not found
nospectre_v1 |cmdline| self_protection |defconfig | is not set | OK: is not found
nospectre_v2 |cmdline| self_protection |defconfig | is not set | OK: is not found
nospectre_bhb |cmdline| self_protection |defconfig | is not set | OK: is not found
arm64.nobti |cmdline| self_protection |defconfig | is not set | OK: is not found
arm64.nopauth |cmdline| self_protection |defconfig | is not set | OK: is not found
arm64.nomte |cmdline| self_protection |defconfig | is not set | OK: is not found
arm64.nogcs |cmdline| self_protection |defconfig | is not set | OK: is not found
iommu.passthrough |cmdline| self_protection |defconfig | 0 | OK: CONFIG_IOMMU_DEFAULT_PASSTHROUGH is "is not set"
rodata |cmdline| self_protection |defconfig | on | OK: rodata is not found
spectre_v2 |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
spectre_v2_user |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
spectre_bhi |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
spec_store_bypass_disable |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
l1tf |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
mds |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
tsx_async_abort |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
srbds |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
mmio_stale_data |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
retbleed |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
spec_rstack_overflow |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
gather_data_sampling |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
reg_file_data_sampling |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
tsa |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
indirect_target_selection |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
vmscape |cmdline| self_protection |defconfig | is not off | FAIL: is off, not found
slab_merge |cmdline| self_protection | kspp | is not set | OK: is not found
slub_merge |cmdline| self_protection | kspp | is not set | OK: is not found
page_alloc.shuffle |cmdline| self_protection | kspp | 1 | FAIL: is not found
hash_pointers |cmdline| self_protection | kspp | always | FAIL: is not found
slab_nomerge |cmdline| self_protection | kspp | is present | FAIL: is not present
init_on_alloc |cmdline| self_protection | kspp | 1 | OK: CONFIG_INIT_ON_ALLOC_DEFAULT_ON is "y"
init_on_free |cmdline| self_protection | kspp | 1 | FAIL: is not found
hardened_usercopy |cmdline| self_protection | kspp | 1 | FAIL: is not found
slab_common.usercopy_fallback |cmdline| self_protection | kspp | is not set | OK: is not found
kfence.sample_interval |cmdline| self_protection | kspp | 100 | FAIL: is not found
lockdown |cmdline| self_protection | kspp |confidentiality| FAIL: is not found
module.sig_enforce |cmdline| self_protection | kspp | 1 | FAIL: is not found
efi |cmdline| self_protection | kspp |*disable_early_pci_dma*| FAIL: is not found
randomize_kstack_offset |cmdline| self_protection | kspp | 1 | OK: CONFIG_RANDOMIZE_KSTACK_OFFSET_DEFAULT is "y"
mitigations |cmdline| self_protection | kspp | auto,nosmt | FAIL: is not found
intel_iommu |cmdline| self_protection | kspp | on | OK: CONFIG_INTEL_IOMMU_DEFAULT_ON is "y"
iommu.strict |cmdline| self_protection | kspp | 1 | FAIL: is not found
pti |cmdline| self_protection | kspp | on | FAIL: is not found
cfi |cmdline| self_protection | kspp | kcfi | FAIL: is not found
iommu |cmdline| self_protection | clipos | force | FAIL: is not found
tsx |cmdline|cut_attack_surface|defconfig | off | OK: CONFIG_X86_INTEL_TSX_MODE_OFF is "y"
nosmt |cmdline|cut_attack_surface| kspp | is present | FAIL: is not present
vsyscall |cmdline|cut_attack_surface| kspp | none | FAIL: is not found
vdso32 |cmdline|cut_attack_surface| kspp | 0 | OK: CONFIG_COMPAT_VDSO is "is not set"
ia32_emulation |cmdline|cut_attack_surface| kspp | 0 | FAIL: is not found
debugfs |cmdline|cut_attack_surface| grsec | off | FAIL: is not found
sysrq_always_enabled |cmdline|cut_attack_surface|grapheneos| is not set | OK: is not found
bdev_allow_write_mounted |cmdline|cut_attack_surface|a13xp0p0v | 0 | FAIL: is not found
norandmaps |cmdline| harden_userspace |defconfig | is not set | OK: is not found
proc_mem.force_override |cmdline| harden_userspace |a13xp0p0v | never | FAIL: is not found
net.core.bpf_jit_harden |sysctl | self_protection | kspp | 2 | FAIL: is not found
vm.mmap_min_addr |sysctl | self_protection | kspp | 65536 | OK
kernel.oops_limit |sysctl | self_protection |a13xp0p0v | 100 | FAIL: "10000"
kernel.warn_limit |sysctl | self_protection |a13xp0p0v | 100 | FAIL: "0"
kernel.dmesg_restrict |sysctl |cut_attack_surface| kspp | 1 | OK
kernel.perf_event_paranoid |sysctl |cut_attack_surface| kspp | 3 | FAIL: "4"
dev.tty.ldisc_autoload |sysctl |cut_attack_surface| kspp | 0 | FAIL: "1"
kernel.kptr_restrict |sysctl |cut_attack_surface| kspp | 2 | FAIL: "1"
dev.tty.legacy_tiocsti |sysctl |cut_attack_surface| kspp | 0 | OK
user.max_user_namespaces |sysctl |cut_attack_surface| kspp | 0 | FAIL: "63417"
kernel.kexec_load_disabled |sysctl |cut_attack_surface| kspp | 1 | FAIL: "0"
kernel.unprivileged_bpf_disabled |sysctl |cut_attack_surface| kspp | 1 | FAIL: "2"
vm.unprivileged_userfaultfd |sysctl |cut_attack_surface| kspp | 0 | OK
kernel.modules_disabled |sysctl |cut_attack_surface| kspp | 1 | FAIL: "0"
kernel.io_uring_disabled |sysctl |cut_attack_surface| grsec | 2 | FAIL: "0"
kernel.sysrq |sysctl |cut_attack_surface|a13xp0p0v | 0 | FAIL: "176"
net.ipv4.icmp_ignore_bogus_error_responses|sysctl | network_security | cis | 1 | OK
net.ipv4.icmp_echo_ignore_broadcasts |sysctl | network_security | cis | 1 | OK
net.ipv4.conf.all.accept_redirects |sysctl | network_security | cis | 0 | FAIL: "1"
net.ipv4.conf.default.accept_redirects|sysctl | network_security | cis | 0 | FAIL: "1"
net.ipv6.conf.all.accept_redirects |sysctl | network_security | cis | 0 | FAIL: "1"
net.ipv6.conf.default.accept_redirects|sysctl | network_security | cis | 0 | FAIL: "1"
net.ipv4.conf.all.accept_source_route |sysctl | network_security | cis | 0 | OK
net.ipv4.conf.default.accept_source_route|sysctl | network_security | cis | 0 | FAIL: "1"
net.ipv6.conf.all.accept_source_route |sysctl | network_security | cis | 0 | OK
net.ipv6.conf.default.accept_source_route|sysctl | network_security | cis | 0 | OK
net.ipv4.tcp_syncookies |sysctl | network_security | cis | 1 | OK
net.ipv6.conf.all.accept_ra |sysctl | network_security | cis | 0 | FAIL: "1"
net.ipv6.conf.default.accept_ra |sysctl | network_security | cis | 0 | FAIL: "1"
fs.protected_symlinks |sysctl | harden_userspace | kspp | 1 | OK
fs.protected_hardlinks |sysctl | harden_userspace | kspp | 1 | OK
fs.protected_fifos |sysctl | harden_userspace | kspp | 2 | FAIL: "1"
fs.protected_regular |sysctl | harden_userspace | kspp | 2 | OK
fs.suid_dumpable |sysctl | harden_userspace | kspp | 0 | FAIL: "2"
kernel.randomize_va_space |sysctl | harden_userspace | kspp | 2 | OK
kernel.yama.ptrace_scope |sysctl | harden_userspace | kspp | 3 | FAIL: "1"
vm.mmap_rnd_bits |sysctl | harden_userspace |a13xp0p0v | 32 | FAIL: is not found
vm.mmap_rnd_compat_bits |sysctl | harden_userspace |a13xp0p0v | 16 | FAIL: is not found
[+] Config check is finished: 'OK' - 168 / 'FAIL' - 184
С помощью аргумента -g инструмент генерирует фрагмент Kconfig с опциями усиления безопасности для выбранной архитектуры.
Этот фрагмент Kconfig можно объединить с существующей конфигурацией ядра Linux:``` $ ./bin/kernel-hardening-checker -g X86_64 > /tmp/fragment $ cd ~/linux-src/ $ ./scripts/kconfig/merge_config.sh .config /tmp/fragment Using .config as base Merging /tmp/fragment Value of CONFIG_BUG_ON_DATA_CORRUPTION is redefined by fragment /tmp/fragment: Previous value: # CONFIG_BUG_ON_DATA_CORRUPTION is not set New value: CONFIG_BUG_ON_DATA_CORRUPTION=y ...
## Благодарности
Спасибо [участникам][26] и пользователям этого проекта!
## Вопросы и ответы
__В:__ Как все эти параметры ядра влияют на безопасность ядра Linux?
__О:__ Чтобы ответить на этот вопрос, вы можете использовать `kernel-hardening-checker` [источники рекомендаций][24]
и [Карту защиты ядра Linux][4] с её ссылками.
<br />
__В:__ Как отключение `CONFIG_USER_NS` сокращает поверхность атаки? Оно нужно для контейнеров!
__О:__ Да, опция `CONFIG_USER_NS` обеспечивает некоторую изоляцию между пользовательскими программами,
но инструмент рекомендует отключать её, чтобы сократить поверхность атаки __на ядро__.
Обоснование:
- Статья LWN о соответствующем обсуждении в LKML: https://lwn.net/Articles/673597/
- Тред в Twitter о `CONFIG_USER_NS` и безопасности: https://twitter.com/robertswiecki/status/1095447678949953541
- Хороший обзор компромисса между включёнными, отключёнными и доступными только для root пространствами имён пользователей: https://github.com/NixOS/nixpkgs/pull/84522#issuecomment-614640601
<br />
__В:__ KSPP и CLIP OS рекомендуют `CONFIG_PANIC_ON_OOPS=y`. Почему этот инструмент не делает того же?
__О:__ Я не могу поддержать эту рекомендацию, потому что:
- Это снижает надёжность системы (kernel oops — всё ещё не редкая ситуация даже на production-системах)
- Это облегчает атаки типа отказа в обслуживании на всю систему
Вам следует включить `CONFIG_PANIC_ON_OOPS`, если:
- Ваше ядро не сталкивается с oops при типичной нагрузке
- Эпизодическая перезагрузка системы не является проблемой в вашем сценарии использования
Я вижу хороший компромисс, который рекомендует `kernel-hardening-checker`:
- Включите опцию kconfig `CONFIG_BUG`. Если kernel oops происходит в контексте процесса, атакующий/нарушающий процесс завершается. В остальных случаях ядро паникует, что аналогично `CONFIG_PANIC_ON_OOPS=y`.
- Установите опции sysctl `kernel.oops_limit` и `kernel.warn_limit` в `100`, например. С одной стороны, это значение не позволяет легко совершить DoS. С другой стороны, оно не слишком велико, чтобы пропустить попытки эксплуатации уязвимостей, генерирующие много предупреждений ядра или oops.
<br />
__В:__ Почему включение `CONFIG_STATIC_USERMODEHELPER` ломает различные вещи в моей GNU/Linux системе?
Действительно ли мне нужна эта функция?
__О:__ Помощники пользовательского режима ядра Linux могут использоваться для повышения привилегий в эксплойтах ядра
([пример 1][9], [пример 2][10]). `CONFIG_STATIC_USERMODEHELPER` предотвращает этот метод. Но это
требует соответствующей поддержки в пользовательском пространстве: смотрите [пример реализации][11] от
Tycho Andersen [@tych0][12].
<br />
__В:__ А как насчёт влияния на производительность этих функций усиления безопасности?
__О:__ Это непростой вопрос, так как влияние на производительность зависит от рабочей нагрузки системы.
Детальная оценка влияния на производительность функций усиления безопасности Linux находится
в TODO (issue [#66][21]). Есть несколько интересных работ в этой области:
- Ike Devolder [@BlackIkeEagle][7] провёл некоторые тесты производительности и описал результаты в [этой статье][8].
- Fabian Rauscher, Benedict Herzog, Timo Hönig и Daniel Gruss опубликовали статью
["Систематический анализ производительности безопасности ядра и затрат энергии"][28], которая описывает
энергетические и временные накладные расходы смягчения уязвимостей оборудования (CONFIG_CPU_MITIGATIONS).
<br />
__В:__ Есть ли в моём ядре все эти смягчения уязвимостей спекулятивного выполнения на моём оборудовании?
__О:__ Проверки конфигурации ядра недостаточно для ответа на этот вопрос.
Я настоятельно рекомендую использовать инструмент [spectre-meltdown-checker][13], поддерживаемый Stéphane Lesimple [@speed47][14].
<br />
__В:__ Могу ли я легко проверить, какие версии ядра поддерживают тот или иной параметр Kconfig?
__О:__ Да. Смотрите проект [LKDDb][18] (База данных драйверов ядра Linux) от Giacomo Catenazzi [@cateee][19].
Вы можете использовать его для ветки `mainline` или `stable` с [kernel.org][20] или для ваших собственных исходников ядра.
<br />
__В:__ Почему опция `CONFIG_GCC_PLUGINS` автоматически отключается во время компиляции ядра?
__О:__ Это означает, что ваш gcc не поддерживает плагины. Например, если у вас `gcc-14` на Ubuntu,
попробуйте установить пакет `gcc-14-plugin-dev`, это должно помочь.
[1]: https://kspp.github.io/Recommended_Settings
[2]: https://docs.clip-os.org/clipos/kernel.html#configuration
[3]: https://grsecurity.net/
[4]: https://github.com/a13xp0p0v/linux-kernel-defence-map
[5]: https://lwn.net/Articles/791863/
[6]: https://github.com/a13xp0p0v/kernel-hardening-checker/issues/38
[7]: https://github.com/BlackIkeEagle
[8]: https://blog.herecura.eu/blog/2020-05-30-kconfig-hardening-tests/
[9]: https://googleprojectzero.blogspot.com/2018/09/a-cache-invalidation-bug-in-linux.html
[10]: https://a13xp0p0v.github.io/2020/02/15/CVE-2019-18683.html
[11]: https://github.com/tych0/huldufolk
[12]: https://github.com/tych0
[13]: https://github.com/speed47/spectre-meltdown-checker
[14]: https://github.com/speed47
[15]: https://github.com/a13xp0p0v/kernel-hardening-checker/issues/53
[16]: https://github.com/a13xp0p0v/kernel-hardening-checker/pull/54
[17]: https://github.com/a13xp0p0v/kernel-hardening-checker/pull/62
[18]: https://cateee.net/lkddb/web-lkddb/
[19]: https://github.com/cateee/lkddb
[20]: https://kernel.org/
[21]: https://github.com/a13xp0p0v/kernel-hardening-checker/issues/66
[22]: https://github.com/a13xp0p0v/kernel-hardening-checker/issues/56
[23]: https://github.com/a13xp0p0v/kernel-hardening-checker/issues?q=label:kernel_maintainer_feedback
[24]: https://github.com/a13xp0p0v/kernel-hardening-checker#motivation
[25]: https://grapheneos.org/features
[26]: https://github.com/a13xp0p0v/kernel-hardening-checker/graphs/contributors
[27]: https://learn.cisecurity.org/benchmarks
[28]: https://dl.acm.org/doi/epdf/10.1145/3708821.3736197