~vcs-imports/ipfire/ipfire-2.x

Viewing all changes in revision 11842.

  • Committer: Michael Tremer
  • Author(s): Peter Müller
  • Date: 2023-10-20 08:44:26 UTC
  • Revision ID: git-v1:447d0bf51ed17f16880fd5041b3a88dcdec8a648
linux: Disable io_uring

This subsystem has been a frequent source of security vulnerabilities
affecting the Linux kernel; as a result, Google announced on June 14,
2023, that they would disable it in their environment as widely as
possible.

IPFire does not depend on the availability of io_uring. Therefore,
disable this subsystem as well in order to preemptively cut attack
surface.

See also: https://security.googleblog.com/2023/06/learnings-from-kctf-vrps-42-linux.html

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>

expand all expand all

Show diffs side-by-side

added added

removed removed

Lines of Context: