Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-106306

[DEV Task]: New configs in security/Kconfig.hardening

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Task Task
    • Resolution: Done
    • Icon: Undefined Undefined
    • eln
    • None
    • kernel / Security
    • None
    • 1
    • rhel-kernel-security
    • CK-2025-wk35
    • 2
    • False
    • Hide

      None

      Show
      None
    • None

      Hi,

      As part of the ongoing rebase effort, the following configuration
      options need to be reviewed.

      As a reminder, the ARK configuration flow involves moving unreviewed
      configuration options from the pending directory to the ark directory.
      In the diff below, options are removed from the pending directory and
      added to the ark hierarchy. The final options that need to be ACKed
      are the files that are being added to the ark hierarchy.

      If the value for a file that is added should be changed, please reply
      with a better option.

      ~~~
      Symbol: KSTACK_ERASE [=n]
      Type : bool
      Defined at security/Kconfig.hardening:88
      Prompt: Poison kernel stack before returning from syscalls
      Depends on: HAVE_ARCH_KSTACK_ERASE [=y] && (GCC_PLUGINS [=n] || CC_HAS_SANCOV_STACK_DEPTH_CALLBACK [=y])
      Location:
      -> Security options
      -> Kernel hardening options
      -> Memory initialization
      -> Poison kernel stack before returning from syscalls (KSTACK_ERASE [=n])

      ~~~
      Commit: 57fbad15c2ee (stackleak: Rename STACKLEAK to KSTACK_ERASE)

      See Merge Request: https://gitlab.com/cki-project/kernel-ark/-/merge_requests/4016

              rhn-support-vdronov Vladislav Dronov
              gitlab-jira Gitlab-jira-bot Gitlab-redhat
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: