~vcs-imports/ipfire/ipfire-2.x

« back to all changes in this revision

Viewing changes to config/kernel/kernel.config.aarch64-ipfire

  • Committer: Michael Tremer
  • Author(s): Peter Müller
  • Date: 2023-10-20 08:44:26 UTC
  • Revision ID: git-v1:447d0bf51ed17f16880fd5041b3a88dcdec8a648
linux: Disable io_uring

This subsystem has been a frequent source of security vulnerabilities
affecting the Linux kernel; as a result, Google announced on June 14,
2023, that they would disable it in their environment as widely as
possible.

IPFire does not depend on the availability of io_uring. Therefore,
disable this subsystem as well in order to preemptively cut attack
surface.

See also: https://security.googleblog.com/2023/06/learnings-from-kctf-vrps-42-linux.html

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>

Show diffs side-by-side

added added

removed removed

Lines of Context:
229
229
CONFIG_EVENTFD=y
230
230
CONFIG_SHMEM=y
231
231
CONFIG_AIO=y
232
 
CONFIG_IO_URING=y
 
232
# CONFIG_IO_URING is not set
233
233
CONFIG_ADVISE_SYSCALLS=y
234
234
CONFIG_MEMBARRIER=y
235
235
CONFIG_KALLSYMS=y
7821
7821
CONFIG_NLS_UTF8=m
7822
7822
# CONFIG_DLM is not set
7823
7823
# CONFIG_UNICODE is not set
7824
 
CONFIG_IO_WQ=y
7825
7824
# end of File systems
7826
7825
 
7827
7826
#