{"id":38554,"date":"2019-10-31T22:24:30","date_gmt":"2019-10-31T19:24:30","guid":{"rendered":"https:\/\/prohoster.info\/blog\/v-yadro-linux-5-4-prinyaty-patchi-dlya-ogranicheniya-dostupa-root-k-vnutrennostyam-yadra\/"},"modified":"2019-10-31T22:24:30","modified_gmt":"2019-10-31T19:24:30","slug":"v-yadro-linux-5-4-prinyaty-patchi-dlya-ogranicheniya-dostupa-root-k-vnutrennostyam-yadra","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/v-yadro-linux-5-4-prinyaty-patchi-dlya-ogranicheniya-dostupa-root-k-vnutrennostyam-yadra","title":{"rendered":"Patches to restrict root access to the internals of the kernel have been accepted into the Linux kernel 5.4","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Linus Torvalds <noindex><a rel=\"nofollow\" href=\"https:\/\/git.kernel.org\/pub\/scm\/linux\/kernel\/git\/torvalds\/linux.git\/commit\/?id=aefcf2f4b58155d27340ba5f9ddbe9513da8286d\">accepted<\/a><\/noindex> The upcoming release of the Linux kernel 5.4 includes a set of patches \"<noindex><a rel=\"nofollow\" href=\"https:\/\/lkml.org\/lkml\/2019\/9\/10\/856\">option to restrict root access to core internals while operating in session copy mode in RAM. New applications pSynclient and SolveSpace are included. A modified version of the NetworkManager applet has been utilized. Improvements have been made to the BootManager, SFSget, EasyContainerManager, and EasyVersionControl applications.<\/a><\/noindex>\" <noindex><a rel=\"nofollow\" href=\"https:\/\/mjg59.dreamwidth.org\/50577.html\">Samsung and utilized in the firmware of Android smartphones from this company was accepted into the mainline kernel. This move was painfully<\/a><\/noindex>\tDavid Howells (who works at Red Hat) and Matthew Garrett (<noindex><a rel=\"nofollow\" href=\"https:\/\/mjg59.dreamwidth.org\/\">Matthew Garrett<\/a><\/noindex>, developed at Google, to restrict root user access to the kernel. The functionality related to \"lockdown\" has been moved to an optionally loadable LSM module (<noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/Linux_Security_Modules\">Linux Security Module<\/a><\/noindex>) that establishes a barrier between UID 0 and the kernel, limiting certain low-level functionality.<\/p>\n<p>If an attacker manages to execute code with root privileges, they could run their code at the kernel level, for example, by replacing the kernel via kexec or reading\/writing memory through \/dev\/kmem. The most obvious consequence of such activity could be <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=41852\">bypassing<\/a><\/noindex> UEFI Secure Boot or extracting sensitive data stored at the kernel level.<\/p>\n<p>Initially, root restriction functions evolved in the context of enhancing verified boot security, and distributions have long used third-party patches to block UEFI Secure Boot bypass. However, such restrictions were not included in the main kernel due to <noindex><a rel=\"nofollow\" href=\"https:\/\/lwn.net\/Articles\/751061\/\">disagreements<\/a><\/noindex> ) due to concerns about implementation and the potential disruption of existing systems. The \"lockdown\" module incorporates already used patches in distributions that have been reworked into a separate subsystem, independent of UEFI Secure Boot. <\/p>\n<p>In lockdown mode, access to \/dev\/mem, \/dev\/kmem, \/dev\/port, \/proc\/kcore, debugfs, kprobes debug mode, mmiotrace, tracefs, BPF, PCMCIA CIS (Card Information Structure), some ACPI interfaces, and CPU MSR registers is restricted; calls to kexec_file and kexec_load are blocked; sleep mode is prohibited; DMA usage for PCI devices is limited; importing ACPI code from EFI variables is forbidden;<br \/>\nmanipulations with input\/output ports are disallowed, including changing interrupt numbers and input\/output ports for the serial port. <\/p>\n<p>By default, the lockdown module is inactive, and it is built when the SECURITY_LOCKDOWN_LSM option is specified in kconfig and activated through the kernel parameter \"lockdown=\", the control file \"\\\/sys\\\/kernel\\\/security\\\/lockdown\", or build options <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/torvalds\/linux\/blob\/master\/security\/lockdown\/Kconfig\">LOCK_DOWN_KERNEL_FORCE_*<\/a><\/noindex>, which can take the values \"integrity\" and \"confidentiality\". In the first case, it blocks the ability to modify the running kernel from user space, while in the second case, it additionally disables functionalities that can be exploited to extract confidential information from the kernel.<\/p>\n<p>It is important to note that lockdown only restricts the default access capabilities to the kernel, but does not protect against modifications resulting from the exploitation of vulnerabilities. To block changes to the running kernel in the case of exploits, the Openwall project <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=47989\">is being developed<\/a><\/noindex> a separate module <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lkrg\/\">LKRG<\/a><\/noindex> (Linux Kernel Runtime Guard).<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51591\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041b\u0438\u043d\u0443\u0441 \u0422\u043e\u0440\u0432\u0430\u043b\u044c\u0434\u0441 \u043f\u0440\u0438\u043d\u044f\u043b \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u0431\u0443\u0434\u0443\u0449\u0435\u0433\u043e \u0432\u044b\u043f\u0443\u0441\u043a\u0430 \u044f\u0434\u0440\u0430 Linux 5.4 \u043d\u0430\u0431\u043e\u0440 \u043f\u0430\u0442\u0447\u0435\u0439 &#171;lockdown&#171;, \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u043d\u044b\u0439 \u0414\u044d\u0432\u0438\u0434\u043e\u043c \u0425\u043e\u0443\u044d\u043b\u043b\u0441\u043e\u043c (David Howells, \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0432 Red Hat) \u0438 \u041c\u044d\u0442\u044c\u044e \u0413\u0430\u0440\u0440\u0435\u0442\u043e\u043c (Matthew Garrett, \u0440\u0430\u0431\u043e\u0442\u0430\u0435\u0442 \u0432 Google) \u0434\u043b\u044f \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u0438\u044f \u0434\u043e\u0441\u0442\u0443\u043f\u0430 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f root \u043a \u044f\u0434\u0440\u0443. \u0421\u0432\u044f\u0437\u0430\u043d\u043d\u0430\u044f \u0441 &#171;lockdown&#187; \u0444\u0443\u043d\u043a\u0446\u0438\u043e\u043d\u0430\u043b\u044c\u043d\u043e\u0441\u0442\u044c \u0432\u044b\u043d\u0435\u0441\u0435\u043d\u0430 \u0432 \u043e\u043f\u0446\u0438\u043e\u043d\u0430\u043b\u044c\u043d\u043e \u0437\u0430\u0433\u0440\u0443\u0436\u0430\u0435\u043c\u044b\u0439 LSM-\u043c\u043e\u0434\u0443\u043b\u044c (Linux Security Module), \u0443\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u044e\u0449\u0438\u0439 \u0431\u0430\u0440\u044c\u0435\u0440 \u043c\u0435\u0436\u0434\u0443 UID 0 \u0438 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-38554","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041b\u0438\u043d\u0443\u0441 \u0422\u043e\u0440\u0432\u0430\u043b\u044c\u0434\u0441 \u043f\u0440\u0438\u043d\u044f\u043b \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u0431\u0443\u0434\u0443\u0449\u0435\u0433\u043e \u0432\u044b\u043f\u0443\u0441\u043a\u0430.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/v-yadro-linux-5-4-prinyaty-patchi-dlya-ogranicheniya-dostupa-root-k-vnutrennostyam-yadra\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412 \u044f\u0434\u0440\u043e Linux 5.4 \u043f\u0440\u0438\u043d\u044f\u0442\u044b \u043f\u0430\u0442\u0447\u0438 \u0434\u043b\u044f \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u0438\u044f \u0434\u043e\u0441\u0442\u0443\u043f\u0430 root \u043a \u0432\u043d\u0443\u0442\u0440\u0435\u043d\u043d\u043e\u0441\u0442\u044f\u043c \u044f\u0434\u0440\u0430 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041b\u0438\u043d\u0443\u0441 \u0422\u043e\u0440\u0432\u0430\u043b\u044c\u0434\u0441 \u043f\u0440\u0438\u043d\u044f\u043b \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u0431\u0443\u0434\u0443\u0449\u0435\u0433\u043e \u0432\u044b\u043f\u0443\u0441\u043a\u0430.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/v-yadro-linux-5-4-prinyaty-patchi-dlya-ogranicheniya-dostupa-root-k-vnutrennostyam-yadra\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:24:30+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:24:30+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Patches to limit root access to the internals of the kernel have been accepted into Linux kernel 5.4 | ProHoster","description":"Linus Torvalds has included it in the upcoming release.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/v-yadro-linux-5-4-prinyaty-patchi-dlya-ogranicheniya-dostupa-root-k-vnutrennostyam-yadra","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412 \u044f\u0434\u0440\u043e Linux 5.4 \u043f\u0440\u0438\u043d\u044f\u0442\u044b \u043f\u0430\u0442\u0447\u0438 \u0434\u043b\u044f \u043e\u0433\u0440\u0430\u043d\u0438\u0447\u0435\u043d\u0438\u044f \u0434\u043e\u0441\u0442\u0443\u043f\u0430 root \u043a \u0432\u043d\u0443\u0442\u0440\u0435\u043d\u043d\u043e\u0441\u0442\u044f\u043c \u044f\u0434\u0440\u0430 | ProHoster","og:description":"\u041b\u0438\u043d\u0443\u0441 \u0422\u043e\u0440\u0432\u0430\u043b\u044c\u0434\u0441 \u043f\u0440\u0438\u043d\u044f\u043b \u0432 \u0441\u043e\u0441\u0442\u0430\u0432 \u0431\u0443\u0434\u0443\u0449\u0435\u0433\u043e \u0432\u044b\u043f\u0443\u0441\u043a\u0430.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/v-yadro-linux-5-4-prinyaty-patchi-dlya-ogranicheniya-dostupa-root-k-vnutrennostyam-yadra","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:24:30+00:00","article:modified_time":"2019-10-31T19:24:30+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"38554","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 22:31:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:07:39","updated":"2026-01-23 22:31:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/38554","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=38554"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/38554\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=38554"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=38554"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=38554"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}