Quote from https://capsule8.com/blog/kernel-configuration-glossary/: > Significance: Critical > > This option checks for obviously wrong memory regions when copying memory > to/from the kernel (via copy_to_user() and copy_from_user() functions) by > ejecting memory ranges that are larger than the specified heap object span > multiple separately allocated pages are not on the process stack or are part of > the kernel text. This kills entire classes of heap overflow exploits and > similar kernel memory exposures.
https://patchwork.ipfire.org/patch/3160/
https://git.ipfire.org/?p=ipfire-2.x.git;a=commit;h=e4d1f968695b6f8d020cd8bf5a650402a61d46ad
https://blog.ipfire.org/post/ipfire-2-25-core-update-146-is-available-for-testing
https://blog.ipfire.org/post/ipfire-2-25-core-update-146-released