]> git.ipfire.org Git - ipfire-3.x.git/blob - setup/sysctl/kernel-hardening.conf
33e096c7ce5036574ab8d025b37efc284a995ee7
[ipfire-3.x.git] / setup / sysctl / kernel-hardening.conf
1 # Try to keep kernel address exposures out of various /proc files (kallsyms, modules, etc).
2 kernel.kptr_restrict = 2
3
4 # Avoid kernel memory address exposures via dmesg.
5 kernel.dmesg_restrict = 1
6
7 # Improve KASLR effectiveness for mmap.
8 vm.mmap_rnd_bits = 32
9 vm.mmap_rnd_compat_bits = 16