diff options
| author | Mimi Zohar <[email protected]> | 2018-07-13 18:05:58 +0000 |
|---|---|---|
| committer | James Morris <[email protected]> | 2018-07-16 19:31:57 +0000 |
| commit | 16c267aac86b463b1fcccd43c89f4c8e5c5c86fa (patch) | |
| tree | 550e6fcb00d732a3c018b3258302f8ffd61a4379 /drivers/base/firmware_loader/fallback.c | |
| parent | kexec: add call to LSM hook in original kexec_load syscall (diff) | |
| download | kernel-16c267aac86b463b1fcccd43c89f4c8e5c5c86fa.tar.gz kernel-16c267aac86b463b1fcccd43c89f4c8e5c5c86fa.zip | |
ima: based on policy require signed kexec kernel images
The original kexec_load syscall can not verify file signatures, nor can
the kexec image be measured. Based on policy, deny the kexec_load
syscall.
Signed-off-by: Mimi Zohar <[email protected]>
Cc: Eric Biederman <[email protected]>
Cc: Kees Cook <[email protected]>
Reviewed-by: Kees Cook <[email protected]>
Signed-off-by: James Morris <[email protected]>
Diffstat (limited to 'drivers/base/firmware_loader/fallback.c')
0 files changed, 0 insertions, 0 deletions
