no longer disable MSR by default

fixes https://github.com/Kicksecure/security-misc/issues/215
This commit is contained in:
Patrick Schleizer 2024-04-01 02:55:59 -04:00
parent d9ac01ba5c
commit 7dba3fb7be
No known key found for this signature in database
GPG Key ID: CB8D50BB77BB3C48
2 changed files with 2 additions and 11 deletions

View File

@ -33,7 +33,8 @@ install video1394 /usr/bin/disabled-firewire-by-security-misc
## Disable CPU MSRs as they can be abused to write to arbitrary memory.
## https://security.stackexchange.com/questions/119712/methods-root-can-use-to-elevate-itself-to-kernel-mode
install msr /usr/bin/disabled-msr-by-security-misc
## https://github.com/Kicksecure/security-misc/issues/215
#install msr /usr/bin/disabled-msr-by-security-misc
## Disables unneeded network protocols that will likely not be used as these may have unknown vulnerabilties.
## Credit to Tails (https://tails.boum.org/blueprint/blacklist_modules/) for some of these.

View File

@ -1,10 +0,0 @@
#!/bin/bash
## Copyright (C) 2019 - 2023 ENCRYPTED SUPPORT LP <adrelanos@whonix.org>
## See the file COPYING for copying conditions.
## Alerts the user that a kernel module failed to load due to it being blacklisted by default.
echo "$0: ERROR: This CPU MSR kernel module is disabled by package security-misc by default. See the configuration file /etc/modprobe.d/30_security-misc.conf | args: $@" >&2
exit 1