mirror of
https://github.com/Kicksecure/security-misc.git
synced 2025-07-12 17:00:32 +07:00
set kernel boot parameter l1tf=full,force
and nosmt=force
https://forums.whonix.org/t/should-all-kernel-patches-for-cpu-bugs-be-unconditionally-enabled-vs-performance-vs-applicability/7647/17
This commit is contained in:
2
debian/control
vendored
2
debian/control
vendored
@ -70,6 +70,8 @@ Description: enhances misc security settings
|
||||
vulnerabilities.
|
||||
.
|
||||
* All mitigations for the MDS vulnerability are enabled.
|
||||
.
|
||||
* Enables mitigations for the L1TF (L1 Terminal Fault) vulnerability.
|
||||
.
|
||||
* A systemd service clears System.map on boot as these contain kernel symbols
|
||||
that could be useful to an attacker.
|
||||
|
Reference in New Issue
Block a user