Linus Torvalds as part of the upcoming release of the Linux kernel 5.4 set of patches â«, by David Howells (works at Red Hat) and Matthew Garrett (, works at Google) to restrict root user access to the kernel. The functionality related to âlockdownâ has been moved to an optionally loadable LSM module (), which establishes a barrier between UID 0 and the kernel, limiting certain low-level functionality.
If an attacker gains code execution with root privileges as a result of an attack, they can execute their code at the kernel level, for example, by replacing the kernel using kexec or reading/writing memory via /dev/kmem. The most obvious consequence of such activity may be UEFI Secure Boot or extracting sensitive data stored at the kernel level.
Initially, the functions for limiting root were developed in the context of enhancing the security of verified boot, and distributions have long employed third-party patches to block UEFI Secure Boot bypass. However, such restrictions were not incorporated into the main kernel due to on their implementation and concerns about disruption of existing systems. The âlockdownâ module has incorporated already used in distributions patches, which were reworked into a separate subsystem not tied to UEFI Secure Boot.
In lockdown mode, access to /dev/mem, /dev/kmem, /dev/port, /proc/kcore, debugfs, kprobes debug mode, mmiotrace, tracefs, BPF, PCMCIA CIS (Card Information Structure), certain ACPI interfaces, and CPU MSR registers is restricted, calls to kexec_file and kexec_load are blocked, sleep mode is prohibited, the use of DMA for PCI devices is limited, importing ACPI code from EFI variables is forbidden,
I/O port manipulations are not allowed, including changing the interrupt number and I/O port for the serial port.
By default, the lockdown module is not active, it is built when specifying the SECURITY_LOCKDOWN_LSM option in kconfig and activated via the kernel parameter âlockdown=â, the control file â/sys/kernel/security/lockdownâ, or build options , tĂ« cilat mund tĂ« kenĂ« vlera «integritet» dhe «konfidencialitet». NĂ« rastin e parĂ« bllokohen mundĂ«sitĂ« qĂ« lejojnĂ« ndryshimin e bĂ«rthamĂ«s nĂ« punĂ« nga hapĂ«sira e pĂ«rdoruesit, ndĂ«rsa nĂ« rastin e dytĂ«, pĂ«rveç kĂ«saj, çaktivizohet funksionaliteti qĂ« mund tĂ« pĂ«rdoret pĂ«r nxjerrjen e informacionit konfidencial nga bĂ«rthama.
Në të njëjtën kohë, është e rëndësishme të theksohet se lockdown-i vetëm kufizon mundësitë standarde të aksesit në bërthamë, por nuk mbron nga modifikimet si rezultat i shfrytëzimit të dobësive. Për të bllokuar ndryshimet në bërthamën në punë kur përdoren eksploit, projekti Openwall modulin e veçantë (Linux Kernel Runtime Guard).
Burimi: opennet.ru
