From: Ben Hutchings Date: Sun, 4 Aug 2019 23:29:11 +0000 (+0100) Subject: hamradio: Disable auto-loading as mitigation against local exploits X-Git-Tag: archive/raspbian/5.18.5-1+rpi1^2~49 X-Git-Url: https://dgit.raspbian.org/?a=commitdiff_plain;h=4f84ea1c0516638ad11794117cdf08d4aedb77d6;p=linux.git hamradio: Disable auto-loading as mitigation against local exploits Forwarded: not-needed We can mitigate the effect of vulnerabilities in obscure protocols by preventing unprivileged users from loading the modules, so that they are only exploitable on systems where the administrator has chosen to load the protocol. The 'ham' radio protocols (ax25, netrom, rose) are not actively maintained or widely used. Therefore disable auto-loading. Signed-off-by: Ben Hutchings Gbp-Pq: Topic debian Gbp-Pq: Name hamradio-disable-auto-loading-as-mitigation-against-local-exploits.patch --- diff --git a/net/ax25/af_ax25.c b/net/ax25/af_ax25.c index 289f355e185..1c5e6431a57 100644 --- a/net/ax25/af_ax25.c +++ b/net/ax25/af_ax25.c @@ -2038,7 +2038,7 @@ module_init(ax25_init); MODULE_AUTHOR("Jonathan Naylor G4KLX "); MODULE_DESCRIPTION("The amateur radio AX.25 link layer protocol"); MODULE_LICENSE("GPL"); -MODULE_ALIAS_NETPROTO(PF_AX25); +/* MODULE_ALIAS_NETPROTO(PF_AX25); */ static void __exit ax25_exit(void) { diff --git a/net/netrom/af_netrom.c b/net/netrom/af_netrom.c index fa9dc2ba394..9cf709c2e32 100644 --- a/net/netrom/af_netrom.c +++ b/net/netrom/af_netrom.c @@ -1488,7 +1488,7 @@ MODULE_PARM_DESC(nr_ndevs, "number of NET/ROM devices"); MODULE_AUTHOR("Jonathan Naylor G4KLX "); MODULE_DESCRIPTION("The amateur radio NET/ROM network and transport layer protocol"); MODULE_LICENSE("GPL"); -MODULE_ALIAS_NETPROTO(PF_NETROM); +/* MODULE_ALIAS_NETPROTO(PF_NETROM); */ static void __exit nr_exit(void) { diff --git a/net/rose/af_rose.c b/net/rose/af_rose.c index 30a1cf4c16c..814b5e4f671 100644 --- a/net/rose/af_rose.c +++ b/net/rose/af_rose.c @@ -1578,7 +1578,7 @@ MODULE_PARM_DESC(rose_ndevs, "number of ROSE devices"); MODULE_AUTHOR("Jonathan Naylor G4KLX "); MODULE_DESCRIPTION("The amateur radio ROSE network layer protocol"); MODULE_LICENSE("GPL"); -MODULE_ALIAS_NETPROTO(PF_ROSE); +/* MODULE_ALIAS_NETPROTO(PF_ROSE); */ static void __exit rose_exit(void) {