diff options
| author | Coiby Xu <[email protected]> | 2022-07-13 07:21:11 +0000 |
|---|---|---|
| committer | Mimi Zohar <[email protected]> | 2022-07-13 14:13:41 +0000 |
| commit | af16df54b89dee72df253abc5e7b5e8a6d16c11c (patch) | |
| tree | d236aeb2c9b99d9e452b6382f016d3e1bc92fc8f /scripts/clang-tools/gen_compile_commands.py | |
| parent | ima: Fix a potential integer overflow in ima_appraise_measurement (diff) | |
| download | kernel-af16df54b89dee72df253abc5e7b5e8a6d16c11c.tar.gz kernel-af16df54b89dee72df253abc5e7b5e8a6d16c11c.zip | |
ima: force signature verification when CONFIG_KEXEC_SIG is configured
Currently, an unsigned kernel could be kexec'ed when IMA arch specific
policy is configured unless lockdown is enabled. Enforce kernel
signature verification check in the kexec_file_load syscall when IMA
arch specific policy is configured.
Fixes: 99d5cadfde2b ("kexec_file: split KEXEC_VERIFY_SIG into KEXEC_SIG and KEXEC_SIG_FORCE")
Reported-and-suggested-by: Mimi Zohar <[email protected]>
Signed-off-by: Coiby Xu <[email protected]>
Signed-off-by: Mimi Zohar <[email protected]>
Diffstat (limited to 'scripts/clang-tools/gen_compile_commands.py')
0 files changed, 0 insertions, 0 deletions
