Kernel-hardening archive mirror
 help / color / mirror / Atom feed
- recent:[subjects (threaded)|topics (new)|topics (active)]
2024-02-05  7:45 [ANNOUNCE] CFP: Linux Security Summit Europe 2024
2023-11-29 21:19 [ANNOUNCE] CFP: Linux Security Summit North America 2024
2023-08-28 16:41 [PATCH v3 0/1] Restrict access to TIOCLINUX 13+ messages
2023-08-28 12:21 [PATCH v2 0/1] Restrict access to TIOCLINUX 4+ messages
2023-08-25 21:14 [PATCH] slub: Introduce CONFIG_SLUB_RCU_DEBUG 7+ messages
2023-08-22 14:39 Re: [PATCH v3 0/5] Landlock: IOCTL support - TTY restrictions RFC
2023-05-04 21:30 [PATCH] sysctl: add config to make randomize_va_space RO 10+ messages
2023-04-17  8:35 [ANNOUNCE] [CFP] Linux Security Summit Europe (LSS-EU)
2023-04-10 10:06 Per-process flag set via prctl() to deny module loading? 6+ messages
2023-04-03 12:06 Re: [PATCH RFC] Randomized slab caches for kmalloc()
2023-04-02 14:08 [PATCH] Restrict access to TIOCLINUX 13+ messages
2023-02-14 10:33 Re: [PATCH] mm/slab: always use cache from obj 4+ messages
2023-01-25 15:29 RE: Linux guest kernel threat model for Confidential Computing 39+ messages
2023-01-20 22:24 [ANNOUNCE] Linux Security Summit North Americ (LSS-NA) CfP
2023-01-16 19:14 [PATCH] fs: Use CHECK_DATA_CORRUPTION() when kernel bugs are detected 5+ messages
2022-12-18 19:29 Isolating abstract sockets 18+ messages
2022-12-01 20:09 Reducing runtime complexity 7+ messages
2022-11-07 20:13 [PATCH] exit: Put an upper limit on how often we can oops 13+ messages
2022-10-09  6:32 [Self-introduction] - Paulo Almeida 3+ messages
2022-06-29  6:04 [PATCH v2] stack: Declare {randomize_,}kstack_offset to fix Sparse warnings 2+ messages
2022-06-29  3:29 [PATCH] stack: Declare {randomize_,}kstack_offset to fix Sparse warnings 3+ messages
2022-06-01 15:41 Re: Possibility of merge of disable icotl TIOCSTI patch 2+ messages
2022-05-18 15:50 [ANNOUNCE][CFP] Linux Security Summit Europe 2022
2022-05-08 14:56 [PATCH] Decouple slub_debug= from no_hash_pointers again 2+ messages
2022-04-10 19:34 Kernel Self Protection Project: slub_debug=ZF 2+ messages
2022-03-21  9:39 OOB accesses in ax88179_rx_fixup() (in USB network card driver) - variants 2+ messages
2022-03-19 12:10 CVE Proofs of Concept
2022-03-18  0:00 Large post detailing recent Linux RNG improvements 4+ messages
2022-02-07 22:24 [ANNOUNCE][CFP] Linux Security Summit North America 2022 2+ messages
2022-02-04  6:53 [PATCH] Add ability to disallow idmapped mounts 7+ messages
2022-01-05 16:02 [PATCH v3 1/3] x86: Implement arch_prctl(ARCH_VSYSCALL_CONTROL) to disable vsyscall 13+ messages
2022-01-04 15:50 [PATCH v18 0/4] Add trusted_for(2) (was O_MAYEXEC) 5+ messages
2021-12-16 18:50 [PATCH v2] x86: Implement arch_prctl(ARCH_VSYSCALL_CONTROL) to disable vsyscall 3+ messages
2021-12-04 17:13 [PATCH] net: prestera: replace zero-length array with flexible-array member 4+ messages
2021-11-26 13:47 [PATCH] x86: Implement arch_prctl(ARCH_VSYSCALL_LOCKOUT) to disable vsyscall 7+ messages
2021-11-21  0:42 I'm Jordan; New Kernel Developer Here!
2021-11-15 18:53 [PATCH v17 0/3] Add trusted_for(2) (was O_MAYEXEC) 9+ messages
2021-11-10 19:06 [PATCH v16 0/3] Add trusted_for(2) (was O_MAYEXEC) 10+ messages
2021-10-27 23:32 [PATCH v2 0/2] Introduce the pkill_on_warn parameter 32+ messages
2021-10-21  0:29 Re: An analysis of current and potential security mitigations based on a TIOCSPGRP exploit 2+ messages
2021-10-12 19:24 [PATCH v15 0/3] Add trusted_for(2) (was O_MAYEXEC) 10+ messages
2021-10-08 10:48 [PATCH v14 0/3] Add trusted_for(2) (was O_MAYEXEC) 12+ messages
2021-10-07 18:23 [PATCH v13 0/3] Add trusted_for(2) (was O_MAYEXEC) 10+ messages
2021-09-29 18:58 [PATCH] Introduce the pkill_on_warn boot parameter 33+ messages
2021-09-19 20:44 Self introduction
2021-09-02 16:13 Re: Landlock news #1
2021-08-30 23:59 [RFC PATCH v2 08/19] x86/mm/cpa: Add get_grouped_page_atomic() 40+ messages
2021-08-17  4:03 Re: [PATCH v11 5/9] Reimplement RLIMIT_MSGQUEUE on top of ucounts 9+ messages
2021-07-01 23:55 Re: [PATCH v8 3/8] security/brute: Detect a brute force attack 6+ messages
2021-06-26  3:21 [PATCH 1/2] seq_buf: fix overflow in seq_buf_putmem_hex() 2+ messages
2021-06-25 15:53 [PATCH 2/2] seq_buf: Make trace_seq_putmem_hex() support data longer than 8 4+ messages
2021-06-24 13:16 [PATCH] seq_buf: let seq_buf_putmem_hex support len larger than 8 7+ messages
2021-06-07 10:21 Re: KASAN: use-after-free Read in hci_chan_del 7+ messages
2021-06-07  7:38 Re: [PATCH v4] bpf: core: fix shift-out-of-bounds in ___bpf_prog_run 18+ messages
2021-06-05 15:03 [PATCH v8 0/8] Fork brute force attack mitigation 13+ messages
2021-05-21 17:24 [PATCH v7 0/7] Fork brute force attack mitigation 12+ messages
2021-05-07 16:15 New mailing list for Landlock LSM user space discussions
2021-05-05  0:30 [PATCH RFC 1/9] list: Support getting most recent element in list_lru 32+ messages
2021-04-22 15:41 [PATCH v34 00/13] Landlock LSM 17+ messages
2021-04-22 12:27 [PATCH v11 1/9] Increase size of ucounts to atomic_long_t 15+ messages
2021-04-07 17:51 Re: Notify special task kill using wait* functions 8+ messages
2021-04-07 17:08 [PATCH v10 0/9] Count rlimits in each user namespace 21+ messages
2021-04-07 16:07 [PATCH v33 00/12] Landlock LSM 16+ messages
2021-04-01 23:23 [PATCH v10 0/6] Optionally randomize kernel stack offset each syscall 9+ messages
2021-04-01 20:59 Re: [PATCH v8 0/6] Optionally randomize kernel stack offset each syscall 2+ messages
2021-04-01 20:51 [PATCH v32 00/12] Landlock LSM 13+ messages
2021-03-31 20:54 [PATCH v9 0/6] Optionally randomize kernel stack offset each syscall 9+ messages
2021-03-30 20:57 [PATCH v8 0/6] Optionally randomize kernel stack offset each syscall 19+ messages
2021-03-29  7:26 two potential randstruct improvements 3+ messages
2021-03-26 23:12 Re: [PATCH v5 1/1] fs: Allow no_new_privs tasks to call chroot(2) 2+ messages
2021-03-24 19:15 [PATCH v31 00/12] Landlock LSM 20+ messages
2021-03-23 20:59 [PATCH v9 0/8] Count rlimits in each user namespace 15+ messages
2021-03-19 21:28 [PATCH v7 2/6] init_on_alloc: Optimize static branches 14+ messages
2021-03-16 20:42 [PATCH v30 00/12] Landlock LSM 49+ messages
2021-03-16 20:36 [PATCH v5 0/1] Unprivileged chroot 11+ messages
2021-03-16 17:01 [PATCH v4 0/1] Unprivileged chroot 9+ messages
2021-03-15 18:02 [PATCH v6 1/6] jump_label: Provide CONFIG-driven build state defaults 9+ messages
2021-03-11 10:52 [PATCH v3 0/1] Unprivileged chroot 4+ messages
2021-03-10 18:18 [PATCH v2 0/1] Unprivileged chroot 6+ messages
2021-03-10 16:09 [PATCH v1 0/1] Unprivileged chroot 8+ messages
2021-03-10 12:01 [PATCH v8 0/8] Count rlimits in each user namespace 15+ messages
2021-03-09 21:42 [PATCH v5 1/7] mm: Restore init_on_* static branch defaults 12+ messages
2021-03-07 11:30 [PATCH v6 0/8] Fork brute force attack mitigation 31+ messages
2021-02-27 15:30 [PATCH v5 0/8] Fork brute force attack mitigation 27+ messages
2021-02-27 15:09 [PATCH v4 0/8] Fork brute force attack mitigation 2+ messages
2021-02-25 19:06 [PATCH v29 00/12] Landlock LSM 13+ messages
2021-02-25  4:42 [PATCH v1 1/1] Kernel Config to make randomize_va_space read-only. 2+ messages
2021-02-24  3:53 [PATCH v1 1/1] Kernel Config to make randomize_va_space read-only. 2+ messages
2021-02-22 15:12 [PATCH 00/20] Manual replacement of all strlcpy in favor of strscpy 46+ messages
2021-02-22  9:56 [PATCH v7 0/7] Count rlimits in each user namespace 17+ messages
2021-02-15 12:41 [PATCH v6 0/7] Count rlimits in each user namespace 18+ messages
2021-02-11  5:51 Fine-grained Forward CFI on top of Intel CET / IBT 4+ messages
2021-02-08 19:59 [ANNOUNCE][CFP] Linux Security Summit 2021 4+ messages
2021-02-05 17:31 Joining the general Linux kernel hardening mailing list
2021-02-02 16:26 [PATCH v28 00/12] Landlock LSM 28+ messages
2021-02-01 17:47 forkat(int pidfd), execveat(int pidfd), other awful things? 14+ messages
2021-02-01 14:18 [PATCH v5 0/7] Count rlimits in each user namespace 10+ messages
2021-01-22 13:00 [PATCH v4 0/7] Count rlimits in each user namespace 8+ messages
2021-01-21 20:51 [PATCH v27 00/12] Landlock LSM 17+ messages
2021-01-21 18:45 [PATCH kspp-next] kbuild: prevent CC_FLAGS_LTO self-bloating on recursive rebuilds 2+ messages
2021-01-15 14:57 [RFC PATCH v3 0/8] Count rlimits in each user namespace 22+ messages
2021-01-10 20:41 linux-hardening list archive
2021-01-10 17:33 [RFC PATCH v2 0/8] Count rlimits in each user namespace 15+ messages
2020-12-28  7:04 [PATCH 04/13] x86/extable: Introduce _ASM_EXTABLE_UA for uaccess fixups 2+ messages
2020-12-12 20:08 Kernel complexity 5+ messages
2020-12-11 18:46 [PATCH v9 00/16] Add support for Clang LTO 40+ messages
2020-12-09 19:28 [PATCH v26 00/12] Landlock LSM 25+ messages
2020-12-04 15:37 [PRE-REVIEW PATCH 0/2] Remove all strlcpy in favor of strscpy 4+ messages
2020-12-03 17:31 [PATCH v12 0/3] Add trusted_for(2) (was O_MAYEXEC) 10+ messages
2020-12-01 21:36 [PATCH v8 00/16] Add support for Clang LTO 51+ messages
2020-12-01 19:23 [PATCH v25 00/12] Landlock LSM 13+ messages
2020-11-27 13:19 [PATCH v2 0/6] aarch64: avoid mprotect(PROT_BTI|PROT_EXEC) [BZ #26831] 20+ messages
2020-11-18 22:42 Re: [PATCH v4] mm: Optional full ASLR for mmap() and mremap() 2+ messages
2020-11-18 22:07 [PATCH v7 00/17] Add support for Clang LTO 50+ messages
2020-11-12 20:51 [PATCH v24 00/12] Landlock LSM 27+ messages
2020-11-03 18:20 [PATCH v23 00/12] Landlock LSM 15+ messages
2020-11-03 10:25 [PATCH 0/4] aarch64: avoid mprotect(PROT_BTI|PROT_EXEC) [BZ #26831] 28+ messages
2020-11-02 16:50 [RFC PATCH v1 0/4] Per user namespace rlimits 12+ messages
2020-10-27 20:03 [PATCH v22 00/12] Landlock LSM 37+ messages
2020-10-25 13:45 [PATCH v2 0/8] Fork brute force attack mitigation 15+ messages
2020-10-22 20:02 Re: BTI interaction between seccomp filters in systemd and glibc mprotect calls, causing service failures 12+ messages
2020-10-19 18:28 [PATCH] mm, hugetlb: Avoid double clearing for hugetlb pages 17+ messages
2020-10-19 16:49 [RESEND PATCH v11 0/3] Add trusted_for(2) (was O_MAYEXEC) 6+ messages
2020-10-13  0:31 [PATCH v6 00/25] Add support for Clang LTO 73+ messages
2020-10-11  6:24 Remove all strlcpy() uses in favor of strscpy() (#89) 3+ messages
2020-10-09 16:13 [PATCH v5 00/29] Add support for Clang LTO 40+ messages
2020-10-08 15:30 [PATCH v21 00/12] Landlock LSM 18+ messages
2020-10-06  0:00 [PATCH v2] MAINTAINERS: Change hardening mailing list
2020-10-05 22:53 [PATCH] MAINTAINERS: Change hardening mailing list 3+ messages
2020-10-02 15:16 [PATCH] random32: Restore __latent_entropy attribute on net_rand_state 5+ messages
2020-10-01 17:02 [PATCH v11 0/3] Add trusted_for(2) (was O_MAYEXEC) 6+ messages
2020-09-29 21:46 [PATCH v4 00/29] Add support for Clang LTO 42+ messages
2020-09-29 18:35 [PATCH RFC v2 0/6] Break heap spraying needed for exploiting use-after-free 24+ messages
2020-09-29 17:14 Linux-specific kernel hardening 13+ messages
2020-09-24 15:32 [PATCH v10 0/3] Add trusted_for(2) (was O_MAYEXEC) 4+ messages
2020-09-23 17:38 [PATCH v5 00/10] Function Granular KASLR 15+ messages
2020-09-18 20:14 [PATCH v3 00/30] Add support for Clang LTO 38+ messages
2020-09-16 15:08 [PATCH v2 0/4] [RFC] Implement Trampoline File Descriptor 52+ messages
2020-09-10 20:21 [RFC PATCH 1/6] security/fbfam: Add a Kconfig to enable the fbfam feature 45+ messages
2020-09-10 16:46 [RFC PATCH v9 0/3] Add introspect_access(2) (was O_MAYEXEC) 17+ messages
2020-09-10 13:48 [PATCH] sched.h: drop in_ubsan field when UBSAN is in trap mode 5+ messages
2020-09-08  7:59 [RFC PATCH v8 0/3] Add support for AT_INTERPRETED (was O_MAYEXEC) 24+ messages
2020-09-06 14:20 [RFC PATCH 0/9] Fork brute force attack mitigation (fbfam) 4+ messages
2020-09-06 12:15 [RFC PATCH 0/9] Fork brute force attack mitigation (fbfam) 2+ messages
2020-08-27 14:58 [PATCH v6 0/3] io_uring: add restrictions to support untrusted applications and guests 11+ messages
2020-08-27 13:40 [PATCH v5 0/3] io_uring: add restrictions to support untrusted applications and guests 11+ messages
2020-08-27  9:43 Re: [PATCH] scripts: Add intended executable mode and SPDX license 13+ messages
2020-08-27  5:26 [PATCH v3 4/6] powerpc: Introduce temporary mm 11+ messages
2020-08-19 22:18 init_on_alloc/init_on_free boot options 3+ messages
2020-08-18  2:34 usercopy arch_within_stack_frames() is a no-op in almost all modern kernel configurations 2+ messages
2020-08-15 17:09 [PATCH v2] overflow: Add __must_check attribute to check_*() helpers 5+ messages
2020-08-13 15:32 [PATCH v4 1/3] io_uring: use an enumeration for io_uring_register(2) opcodes 19+ messages
2020-08-13 15:19 [PATCH RFC 0/2] Break heap spraying needed for exploiting use-after-free 19+ messages
2020-08-12 21:51 [PATCH] overflow: Add __must_check attribute to check_*() helpers 5+ messages
2020-08-03 18:29 [RFC] saturate check_*_overflow() output? 7+ messages
2020-08-02 21:58 [PATCH v20 00/12] Landlock LSM 18+ messages
2020-07-30 16:01 Alternative CET ABI 5+ messages
2020-07-29  3:15 [PATCH 1/2] kbuild: move shared library build rules to scripts/gcc-plugins/Makefile 3+ messages
2020-07-28 16:00 [PATCH v3 1/3] io_uring: use an enumeration for io_uring_register(2) opcodes 5+ messages
2020-07-28 13:10 [PATCH v1 0/4] [RFC] Implement Trampoline File Descriptor 67+ messages
2020-07-27 16:16 Re: [PATCH 12/26] netfilter: switch nf_setsockopt to sockptr_t 4+ messages
2020-07-23 17:12 [PATCH v7 0/7] Add support for O_MAYEXEC 44+ messages
2020-07-19 15:50 [PATCH v2 0/2] kernel/trace: Remove function callback casts 18+ messages
2020-07-17 16:59 [PATCH v4 00/10] Function Granular KASLR 46+ messages
2020-07-16 12:48 [PATCH RFC v2 0/3] io_uring: add restrictions to support untrusted applications and guests 17+ messages
2020-07-16  3:08 [PATCH 0/3] Modernize tasklet callback API 27+ messages
2020-07-14 18:16 [PATCH v6 0/7] Add support for O_MAYEXEC 25+ messages
2020-07-13 13:50 [PATCH] gcc-plugins: Replace HTTP links with HTTPS ones 2+ messages
2020-07-11 17:42 Clarification about the series to modernize the tasklet api 18+ messages
2020-07-10 14:19 [PATCH RFC 1/3] io_uring: use an enumeration for io_uring_register(2) opcodes 9+ messages
2020-07-09  4:03 [PATCH 0/5] Use per-CPU temporary mappings for patching 14+ messages
2020-07-07 18:09 [PATCH v19 00/12] Landlock LSM 27+ messages
2020-07-04 15:50 [PATCH v2] parisc/kernel/ftrace: Remove function callback casts
2020-06-27 13:43 [PATCH] parisc/kernel/ftrace: Remove function callback casts 3+ messages
2020-06-27 12:54 [PATCH] drivers/s390/char/tty3270: Remove function callback casts 4+ messages
2020-06-26 15:58 [PATCH v3 0/2] arm64/acpi: restrict AML opregion memory access 16+ messages
2020-06-24 20:31 [PATCH 00/22] add support for Clang LTO 213+ messages
2020-06-24 12:33 [PATCH v2 0/5] Improvements of the stackleak gcc plugin 17+ messages
2020-06-23 17:23 [PATCH v3 00/10] Function Granular KASLR 24+ messages
2020-06-23  9:37 [RFC PATCH v2] arm64/acpi: disallow AML memory opregions to access kernel memory 6+ messages
2020-06-23  6:26 Kernel hardening project suggestion: Normalizing ->ctor slabs and TYPESAFE_BY_RCU slabs 9+ messages
2020-06-22 19:31 [PATCH v4 4/5] x86/entry: Enable random_kstack_offset support 19+ messages
2020-06-22  9:27 [RFC PATCH] arm64/acpi: disallow AML memory opregions to access kernel memory 6+ messages
2020-06-18 14:06 [kvm-unit-tests PATCH v2] x86: Add control register pinning tests
2020-06-17 23:26 [kvm-unit-tests RESEND PATCH] x86: Add control register pinning tests
2020-06-17 22:46 [kvm-unit-tests PATCH] x86: Add control register pinning tests 6+ messages
2020-06-17 20:56 [PATCH] tracing: Use linker magic instead of recasting ftrace_ops_list_func() 8+ messages
2020-06-17 19:07 [PATCH 0/4] Paravirtualized Control Register pinning 30+ messages
2020-06-15 10:26 lockdown bypass on mainline kernel for loading unsigned modules 10+ messages
2020-06-15  9:04 Re: [RFC] io_uring: add restrictions to support untrusted applications and guests 10+ messages
2020-06-15  8:51 [PATCH] f2fs: Eliminate usage of uninitialized_var() macro 3+ messages
2020-06-15  4:01 [PATCH] erofs: Eliminate usage of uninitialized_var() macro 5+ messages
2020-06-15  4:00 [PATCH] ACPI: Eliminate usage of uninitialized_var() macro 2+ messages
2020-06-14  7:01 [PATCH] kernel/trace: Remove function callback casts 5+ messages
2020-06-04 13:49 [PATCH 0/5] Improvements of the stackleak gcc plugin 31+ messages
2020-05-30 14:34 [PATCH v5 0/3] drivers/acpi: Remove function callback casts 7+ messages
2020-05-30  9:08 [PATCH v3] firewire: Remove function callback casts 4+ messages
2020-02-26 21:50 [PATCH] x86/mm/init_32: Don't print out kernel memory layout if KASLR 34+ messages
2020-02-13 12:24 [PATCH] gcc-plugins: fix gcc-plugins directory path in documentation 3+ messages
2017-04-04 22:12 [kernel-hardening] [PATCH v2 4/7] bug: Enable DEBUG_CREDENTIALS under BUG_ON_DATA_CORRUPTION 11+ messages

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).