Need activate more hardening option

Bug #1805018 reported by FR. Loïc
260
This bug affects 1 person
Affects Status Importance Assigned to Milestone
linux (Ubuntu)
Confirmed
Medium
Unassigned

Bug Description

Hi,

The current configuration of the linux kernel in Ubuntu is not secure enough.
A simple test [1] of kernel in Ubuntu Disco clearly indicates 53 errors...

Can we discuss possible options to activate by default?

Enable the GCC_PLUGINS* would be for me the bare minimum.

Thanks. Best regards,

[1] https://github.com/a13xp0p0v/kconfig-hardened-check

CVE References

Revision history for this message
FR. Loïc (hackurx) wrote :
Revision history for this message
Ubuntu Kernel Bot (ubuntu-kernel-bot) wrote : Missing required logs.

This bug is missing log files that will aid in diagnosing the problem. While running an Ubuntu kernel (not a mainline or third-party kernel) please enter the following command in a terminal window:

apport-collect 1805018

and then change the status of the bug to 'Confirmed'.

If, due to the nature of the issue you have encountered, you are unable to run this command, please add a comment stating that fact and change the bug status to 'Confirmed'.

This change has been made by an automated script, maintained by the Ubuntu Kernel Team.

Changed in linux (Ubuntu):
status: New → Incomplete
Revision history for this message
FR. Loïc (hackurx) wrote :

No log files is required.

Changed in linux (Ubuntu):
status: Incomplete → Confirmed
Revision history for this message
FR. Loïc (hackurx) wrote :

Current kernel configuration

Changed in linux (Ubuntu):
importance: Undecided → Medium
FR. Loïc (hackurx)
information type: Public → Public Security
Revision history for this message
FR. Loïc (hackurx) wrote :

config-5.0.0-16-generic: 'OK' - 43 / 'FAIL' - 60

Revision history for this message
FR. Loïc (hackurx) wrote :
Revision history for this message
FR. Loïc (hackurx) wrote :

Ubuntu 20.04 LTS (Focal Fossa) :
config check is finished: 'OK' - 57 / 'FAIL' - 79

https://github.com/a13xp0p0v/kconfig-hardened-check/commit/e54cb30a2789c8f8ce15648d72299e243b3b27c1

Revision history for this message
FR. Loïc (hackurx) wrote :
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.