dccp: Disable auto-loading as mitigation against local exploits
authorBen Hutchings <ben@decadent.org.uk>
Thu, 16 Feb 2017 19:09:17 +0000 (19:09 +0000)
committerRaspbian forward porter <root@raspbian.org>
Sun, 30 Oct 2022 17:31:56 +0000 (17:31 +0000)
commitf9c64164b286dae45f2ecf0def24790a1320c7a7
treed21a8bb95875ae01c96e4cc84fd1aecec19b9b4a
parentbf1d70b6e5751f1a1004d6da3d68515ab6deefa1
dccp: Disable auto-loading as mitigation against local exploits

Forwarded: not-needed

We can mitigate the effect of vulnerabilities in obscure protocols by
preventing unprivileged users from loading the modules, so that they
are only exploitable on systems where the administrator has chosen to
load the protocol.

The 'dccp' protocol is not actively maintained or widely used.
Therefore disable auto-loading.

Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
Gbp-Pq: Topic debian
Gbp-Pq: Name dccp-disable-auto-loading-as-mitigation-against-local-exploits.patch
net/dccp/ipv4.c
net/dccp/ipv6.c