New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Qubes processes should use hardening flags #2259

Open
andrewdavidwong opened this Issue Aug 20, 2016 · 0 comments

Comments

Projects
None yet
1 participant
@andrewdavidwong
Member

andrewdavidwong commented Aug 20, 2016

On 2016-08-20 11:32, Lorenzo Lamas wrote:

A quick check in the Fedora 23 VM with Checksec shows all migitations enabled for most processes. Processes from Qubes however are missing migitations.
A short list: (These are the processes that I know are from Qubes, some might be missing)

qubes-db-deamon:No PIE, No Stack Canary, RELRO only partial
qrexec-agent: No Stack Canary, RELRO only partial
qubes-gui: No Stack Canary, RELRO only partial
qrexec-client-c: No Stack Canary, RELRO only partial
qrexec-fork-ser: No Stack Canary, RELRO only partial
icon sender: RELRO only partial

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment