Controls for blocking kernel modules to reduce kernel attack surface
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 48/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Quiet
- Tech stack
- linux, ruby, yaml
- Domain
- operating-systems, security
Research direction
Start by reviewing the attached kernel-modules-baseline-blocklist.yml and the profile's existing CIS-based kernel-module blocklist. Compare the proposed defaults with the current behavior, then determine how specific modules should be whitelisted; done means the expanded defaults and documented whitelist behavior are implemented without blocking required modules.
Written by the indexing model from the issue text.
Description
Description
Multiple Linux kernel local privilege escalation vulnerabilities (Copy Fail, Dirty Frag, Fragnesia) have been found recently in a very short time window. This increased pace of AI-aided vulnerability discovery is only expected to increase. Most of the recent vulnerabilities are in obscure kernel modules that almost body uses, but that can be autoloaded.
Solution
Extend the list of default kernel modules to block. Right now this only includes a handful of obscure filesystems, as recommended by CIS, but this small blocklist is clearly no longer enough.
Also allow whitelisting specific modules.
Attached: my personal list of modules to block by default. Optimized for common virtualized servers. Workstations and GPU servers will need to adjust this list.
kernel-modules-baseline-blocklist.yml
Alternatives
Block all modules that are not in active use. Modulejail uses this approach.
Additional information
No response
- Dominant language
- Ruby
- Stars
- 876
- Forks
- 194
- Avg merge
- 9m
- Merged PRs (30d)
- 1
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from dev-sec/linux-baseline
-
Add two additional PATH env checks for the rule 'os-04'Possibly taken @MikhailAseev claimed this 775 days ago. Openenhancement
Difficulty 2/5 1-3 hours Newbie friendliness 58/100
dev-sec/linux-baseline#188 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 48/100
dev-sec/linux-baseline#173 · 6 comments ·
-
Add file system checks for other shadow and passwd/group filesPossibly taken @cmhe claimed this 1807 days ago. Open
Difficulty 3/5 1-2 days Newbie friendliness 48/100
dev-sec/linux-baseline#161 · 1 comment ·
-
Difficulty 5/5 Over a week Newbie friendliness 25/100
dev-sec/linux-baseline#140 · 7 comments · 5 reactions ·
-
disable rpcbindOpen
Difficulty 4/5 3-5 days Newbie friendliness 35/100
dev-sec/linux-baseline#137 · 3 comments ·
All issues in dev-sec/linux-baseline
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
eurosky-social/eu-haul#32 ·
-
good first issue
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
benbalter/add-to-org#17 ·
-
good first issue
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
benbalter/change_agent#11 ·
-
good first issue
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
benbalter/count-org-loc#20 ·
-
good first issue
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
benbalter/sitemap-parser#33 ·