Restrict /dev/mem and /dev/kmem when securelevel is set.
authorMatthew Garrett <mjg59@srcf.ucam.org>
Fri, 9 Mar 2012 14:28:15 +0000 (09:28 -0500)
committerAurelien Jarno <aurel32@debian.org>
Fri, 2 Mar 2018 07:52:22 +0000 (07:52 +0000)
commit2249e2baa711b51d52156be0a15b0b7425628803
tree5cefdb1d555845a1dd92d6bf9ab17c3102969681
parented79c5eeebeb598db80d832eab61d11f1604c058
Restrict /dev/mem and /dev/kmem when securelevel is set.

Allowing users to write to address space provides mechanisms that may permit
modification of the kernel at runtime. Prevent this if securelevel has been
set.

Signed-off-by: Matthew Garrett <mjg59@srcf.ucam.org>
[bwh: Forward-ported to 4.9: adjust context]

Gbp-Pq: Topic features/all/securelevel
Gbp-Pq: Name restrict-dev-mem-and-dev-kmem-when-securelevel-is-se.patch
drivers/char/mem.c