mount /dev/cdrom to /mnt/cdrom (instead of /mnt/cdrom0) and

nodev,nosuid,noexec

as per:
https://www.debian.org/doc/manuals/securing-debian-manual/ch04s10.en.html

https://github.com/Kicksecure/security-misc/issues/157
This commit is contained in:
Patrick Schleizer 2023-12-25 09:44:51 -05:00
parent 0d9e9780da
commit 2b7aeedb4a
No known key found for this signature in database
GPG Key ID: CB8D50BB77BB3C48

View File

@ -9,7 +9,8 @@ proc /proc pr
## noexec optional
/dev/shm /dev/shm tmpfs nosuid,nodev,noexec 0 0
/dev/cdrom /mnt/cdrom0 iso9660 ro,user,noauto 0 0
## https://www.debian.org/doc/manuals/securing-debian-manual/ch04s10.en.html
/dev/cdrom /mnt/cdrom iso9660 ro,users,nodev,nosuid,noexec 0 0
/boot /boot none bind,remount,nosuid,nodev,noexec 0 0