Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-8810

RFE: Consider enabling the Landlock LSM

Linking RHIVOS CVEs to...Migration: Automation ...XMLWordPrintable

    • kernel-5.14.0-568.el9
    • None
    • 3
    • rhel-sst-kernel-livepatching
    • ssg_core_kernel
    • 25
    • 26
    • 5
    • False
    • Hide

      None

      Show
      None
    • None
    • CK-November-2024, CK-December-2024, CK-February-2025
    • Feature
    • Hide
      .Landlock, a new Linux Security Module (LSM) is released

      RHEL 9.6 introduces Landlock, a new security feature that makes your containers safer. Landlock sets strict rules for processes like Podman to limit access to the file system through the kernel API, defining rules for themselves regardless of privilege level and allowing users to create hard limits over the accessible scope of the processes.

      With Landlock, you can build programs that mitigate potential risks associated with misconfigured or maliciously targeted processes. This makes containers and the whole system more secure.
      Show
      .Landlock, a new Linux Security Module (LSM) is released RHEL 9.6 introduces Landlock, a new security feature that makes your containers safer. Landlock sets strict rules for processes like Podman to limit access to the file system through the kernel API, defining rules for themselves regardless of privilege level and allowing users to create hard limits over the accessible scope of the processes. With Landlock, you can build programs that mitigate potential risks associated with misconfigured or maliciously targeted processes. This makes containers and the whole system more secure.
    • Done
    • None
    • 57,005

      Feature request / new config option: Consider enabling the Landlock LSM

      See:

      It has been enabled in Fedora since the 5.13.4 kernel packages (F34 update and later).

      See initial change in https://gitlab.com/cki-project/kernel-ark/-/merge_requests/1087.

              rysulliv@redhat.com Ryan Sullivan
              travier@redhat.com Timothée Ravier
              Gabriela Fialova
              Štěpán Horáček Štěpán Horáček
              Dennis Li Dennis Li
              Malhar Jivrajani Malhar Jivrajani
              Votes:
              1 Vote for this issue
              Watchers:
              20 Start watching this issue

                Created:
                Updated:
                Resolved: