From a3e657102c5810d31953d5ae8fe5d7b7db4570a6 Mon Sep 17 00:00:00 2001 From: Mikael Voss Date: Wed, 28 Aug 2024 13:24:30 +0200 Subject: [PATCH] =?UTF-8?q?linux:=20Mark=20RANDOMIZE=5FMEMORY=20as=20x86?= =?UTF-8?q?=E2=80=90specific?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- package/linux-hardened/config.nix | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/package/linux-hardened/config.nix b/package/linux-hardened/config.nix index 1072651..f6be423 100644 --- a/package/linux-hardened/config.nix +++ b/package/linux-hardened/config.nix @@ -117,7 +117,6 @@ # Kernel memory base RELOCATABLE = true; RANDOMIZE_BASE = true; - RANDOMIZE_MEMORY = true; # Stack protection STACKPROTECTOR = true; @@ -194,6 +193,8 @@ X86_UMIP = true; X86_USER_SHADOW_STACK = true; + RANDOMIZE_MEMORY = true; + STRICT_SIGALTSTACK_SIZE = true; };