Skip to content

feat: add two kernel hardening parameters#1615

Merged
RoyalOughtness merged 3 commits intosecureblue:livefrom
raja-grewal:slab_debug
Nov 21, 2025
Merged

feat: add two kernel hardening parameters#1615
RoyalOughtness merged 3 commits intosecureblue:livefrom
raja-grewal:slab_debug

Conversation

@raja-grewal
Copy link
Copy Markdown
Contributor

As per the discussion in #1393 (comment).

@HastD
Copy link
Copy Markdown
Collaborator

HastD commented Nov 20, 2025

Is there any risk of slab_debug=FZ leaking sensitive info from the kernel, given that slab_debug is designed as a debugging tool rather than as a security measure? Or is that risk fully mitigated by the use of hash_pointers=always?

@raja-grewal
Copy link
Copy Markdown
Contributor Author

Yes, previous issues all seem resolved now.

See KSPP KSPP/kspp.github.io#8 and Kicksecure/security-misc#253 (comment).

@RoyalOughtness RoyalOughtness enabled auto-merge (squash) November 21, 2025 18:49
@RoyalOughtness RoyalOughtness merged commit 5659687 into secureblue:live Nov 21, 2025
14 checks passed
@raja-grewal raja-grewal deleted the slab_debug branch November 22, 2025 04:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants