Compare commits

...

2 Commits

Author SHA1 Message Date
h7x4
ecc4417e0f base/hardening: ban a few more modules 2026-05-20 16:33:55 +09:00
h7x4
ffce1bd607 base/mitigations: blacklist modules for copyfail and pintheft 2026-05-20 16:33:55 +09:00
2 changed files with 23 additions and 13 deletions

View File

@@ -7,7 +7,13 @@
"ax25" "ax25"
"batman-adv" "batman-adv"
"can" "can"
"dccp"
"ipx"
"llc"
"n-hdlc"
"netrom" "netrom"
"p8022"
"p8023"
"psnap" "psnap"
"rds" "rds"
"rose" "rose"
@@ -23,7 +29,6 @@
"cramfs" "cramfs"
"efs" "efs"
"exofs" "exofs"
"orangefs"
"freevxfs" "freevxfs"
"gfs2" "gfs2"
"hfs" "hfs"
@@ -35,10 +40,12 @@
"nilfs2" "nilfs2"
"ntfs" "ntfs"
"omfs" "omfs"
"orangefs"
"qnx4" "qnx4"
"qnx6" "qnx6"
"sysv" "sysv"
"ubifs" "ubifs"
"udf"
"ufs" "ufs"
# Legacy hardware # Legacy hardware

View File

@@ -2,16 +2,19 @@
{ {
boot.blacklistedKernelModules = [ boot.blacklistedKernelModules = [
"rxrpc" # dirtyfrag # copy.fail
"esp6" # dirtyfrag "af_alg"
"esp4" # dirtyfrag "algif_aead"
]; "algif_hash"
boot.extraModprobeConfig = '' "algif_rng"
# dirtyfrag "algif_skcipher"
install esp4 /bin/false
# dirtyfrag # dirtyfrag / Fragnesia
install esp6 /bin/false "esp4"
# dirtyfrag "esp6"
install rxrpc /bin/false "rxrpc"
'';
# PinTheft
"rds"
];
} }