diff --git a/usr/lib/sysctl.d/990-security-misc.conf b/usr/lib/sysctl.d/990-security-misc.conf index f660d54c..321f3b80 100644 --- a/usr/lib/sysctl.d/990-security-misc.conf +++ b/usr/lib/sysctl.d/990-security-misc.conf @@ -68,6 +68,9 @@ kernel.unprivileged_bpf_disabled=1 net.core.bpf_jit_harden=2 ## Disable asynchronous I/O for all processes. +## Valid only for linux kernel version >= 6.6. +## Command is retained here for future-proofing and completeness. +## https://forums.whonix.org/t/io-uring-security-vulnerabilties/16890/6 kernel.io_uring_disabled=2 #### meta start