Skip to content
Snippets Groups Projects
Commit e6a7b37d authored by Stephen Smalley's avatar Stephen Smalley Committed by Nick Kralevich
Browse files

Restrict mapping low memory.


Label /proc/sys/vm/mmap_min_addr with proc_security to prevent
writing it by any domain other than init.  Also remove memprotect
mmap_zero permission from unconfineddomain so that it cannot pass
the SELinux check over mapping low memory.

Change-Id: Idc189feeb325a4aea26c93396fd0fa7225e79586
Signed-off-by: default avatarStephen Smalley <sds@tycho.nsa.gov>
parent 95e0842e
No related branches found
No related tags found
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment