Bug 12375 - CONFIG_LEGACY_VSYSCALL_NONE is enabled on x86_64 only
Summary: CONFIG_LEGACY_VSYSCALL_NONE is enabled on x86_64 only
Status: ASSIGNED
Alias: None
Product: IPFire
Classification: Unclassified
Component: --- (show other bugs)
Version: 2
Hardware: unspecified All
: Will affect an average number of users Security
Assignee: Peter Müller
QA Contact:
URL:
Keywords:
Depends on:
Blocks: KERNSEC
  Show dependency treegraph
 
Reported: 2020-04-14 15:41 UTC by Peter Müller
Modified: 2020-06-09 17:44 UTC (History)
0 users

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Peter Müller 2020-04-14 15:41:33 UTC
Quote from https://capsule8.com/blog/kernel-configuration-glossary/:

> Significance: High
> 
> There will be no vsyscall mapping at all. This will eliminate any risk of ASLR
> bypass due to the vsyscall fixed address mapping. Attempts to use the vsyscalls
> will be reported to dmesg so that either old or malicious userspace programs
> can be identified.
Comment 1 Peter Müller 2020-06-09 17:39:00 UTC
See also: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=852620
Comment 2 Peter Müller 2020-06-09 17:44:22 UTC
https://patchwork.ipfire.org/patch/3177/