From: Ben Hutchings Date: Thu, 16 Feb 2017 19:09:17 +0000 (+0000) Subject: dccp: Disable auto-loading as mitigation against local exploits X-Git-Tag: archive/raspbian/6.12.27-1+rpi1^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2^2~48 X-Git-Url: https://dgit.raspbian.org/%22http:/www.example.com/cgi/%22https:/%22bookmarks://%22Dat/%22http:/www.example.com/cgi/%22https:/%22bookmarks:/%22Dat?a=commitdiff_plain;h=d2818e11717872affb9a088cf4a062e3ce13ebcc;p=linux.git dccp: Disable auto-loading as mitigation against local exploits Forwarded: not-needed We can mitigate the effect of vulnerabilities in obscure protocols by preventing unprivileged users from loading the modules, so that they are only exploitable on systems where the administrator has chosen to load the protocol. The 'dccp' protocol is not actively maintained or widely used. Therefore disable auto-loading. Signed-off-by: Ben Hutchings Gbp-Pq: Topic debian Gbp-Pq: Name dccp-disable-auto-loading-as-mitigation-against-local-exploits.patch --- diff --git a/net/dccp/ipv4.c b/net/dccp/ipv4.c index 524b7e581a0..59a6a15f9b9 100644 --- a/net/dccp/ipv4.c +++ b/net/dccp/ipv4.c @@ -1093,8 +1093,8 @@ module_exit(dccp_v4_exit); * values directly, Also cover the case where the protocol is not specified, * i.e. net-pf-PF_INET-proto-0-type-SOCK_DCCP */ -MODULE_ALIAS_NET_PF_PROTO_TYPE(PF_INET, 33, 6); -MODULE_ALIAS_NET_PF_PROTO_TYPE(PF_INET, 0, 6); +/* MODULE_ALIAS_NET_PF_PROTO_TYPE(PF_INET, 33, 6); */ +/* MODULE_ALIAS_NET_PF_PROTO_TYPE(PF_INET, 0, 6); */ MODULE_LICENSE("GPL"); MODULE_AUTHOR("Arnaldo Carvalho de Melo "); MODULE_DESCRIPTION("DCCP - Datagram Congestion Controlled Protocol"); diff --git a/net/dccp/ipv6.c b/net/dccp/ipv6.c index 6f5a556f4f6..436917339ea 100644 --- a/net/dccp/ipv6.c +++ b/net/dccp/ipv6.c @@ -1175,8 +1175,8 @@ module_exit(dccp_v6_exit); * values directly, Also cover the case where the protocol is not specified, * i.e. net-pf-PF_INET6-proto-0-type-SOCK_DCCP */ -MODULE_ALIAS_NET_PF_PROTO_TYPE(PF_INET6, 33, 6); -MODULE_ALIAS_NET_PF_PROTO_TYPE(PF_INET6, 0, 6); +/* MODULE_ALIAS_NET_PF_PROTO_TYPE(PF_INET6, 33, 6); */ +/* MODULE_ALIAS_NET_PF_PROTO_TYPE(PF_INET6, 0, 6); */ MODULE_LICENSE("GPL"); MODULE_AUTHOR("Arnaldo Carvalho de Melo "); MODULE_DESCRIPTION("DCCPv6 - Datagram Congestion Controlled Protocol");