Skip to content

Commit

Permalink
Merge pull request #75 from flawedworld/patch-1
Browse files Browse the repository at this point in the history
Blacklist more modules (based on OpenSCAP for RHEL 8)
  • Loading branch information
Patrick Schleizer committed Sep 28, 2020
2 parents ae90107 + a813e7d commit 3684ab5
Showing 1 changed file with 8 additions and 0 deletions.
8 changes: 8 additions & 0 deletions etc/modprobe.d/30_security-misc.conf
Expand Up @@ -44,6 +44,14 @@ install appletalk /bin/false
install psnap /bin/false
install p8023 /bin/false
install p8022 /bin/false
install can /bin/false
install atm /bin/false

# Disable uncommon filesystems to reduce attack surface
install cramfs /bin/false
install vfat /bin/false
install squashfs /bin/false
install udf /bin/false

## Blacklists the vivid kernel module as it's only required for
## testing and has been the cause of multiple vulnerabilities.
Expand Down

0 comments on commit 3684ab5

Please sign in to comment.