Security researcher Hanno Böck raises concerns about Linux kernel attack surface, using recent ESP/IPSEC-related local root exploits as a case study. He argues that Linux distributions ship and auto-load most kernel modules by default, exposing users to vulnerabilities in features they never use. He suggests splitting rarely-used modules like IPSEC into separate optional packages (e.g., linux-modules-ipsec) that aren't installed by default, noting this would have significantly reduced the impact of several recent kernel exploits. He also provides specific kernel config options to disable for those building custom kernels who don't use IPSEC.

2m read timeFrom openwall.com
Post cover image
416 Impressions