Lock down non-regular-file filesystem objects in stateful |
||
Issue descriptionWe've seen numerous attacks against verified boot relying on various non-file filesystem objects (symlinks, FIFOs, etc.). The most recent example is issue 766253 . Expand the LSM started in issue 712814 to block these objects as well.
,
Jan 16
This has been addressed by mortonm@'s work. Assigning and closing :-D |
||
►
Sign in to add a comment |
||
Comment 1 by sheriffbot@chromium.org
, Nov 14Status: Untriaged (was: Available)