Kicksecure / security-misc

Kernel Hardening; Protect Linux User Accounts against Brute Force Attacks; Improve Entropy Collection; Strong Linux User Account Separation; Enhances Misc Security Settings - https://www.kicksecure.com/wiki/Security-misc
https://www.kicksecure.com/wiki/Impressum
Other
505 stars 50 forks source link

BHI mitigation on Intel CPUs #216

Closed raja-grewal closed 5 months ago

raja-grewal commented 5 months ago

Add kernel parameter for new Intel CPU vulnerability.

https://lore.kernel.org/lkml/20220714195236.9311-1-daniel.sneddon@linux.intel.com/ https://www.vusec.net/projects/native-bhi/

This kernel parameter is preemptive and will only take effect once the fixes are backported. LTS kernel version 6.1.85 and above are patched.