Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Blacklist more modules (based on OpenSCAP for RHEL 8) #75

Merged
merged 1 commit into from Sep 28, 2020
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Jump to
Jump to file
Failed to load files.
Diff view
Diff view
8 changes: 8 additions & 0 deletions etc/modprobe.d/30_security-misc.conf
Expand Up @@ -44,6 +44,14 @@ install appletalk /bin/false
install psnap /bin/false
install p8023 /bin/false
install p8022 /bin/false
install can /bin/false
install atm /bin/false

# Disable uncommon filesystems to reduce attack surface
install cramfs /bin/false
install vfat /bin/false
install squashfs /bin/false
install udf /bin/false

## Blacklists the vivid kernel module as it's only required for
## testing and has been the cause of multiple vulnerabilities.
Expand Down