4 ms·
I’ve gone with the KSPP suggestion: # Turn off unprivileged eBPF access. kernel.unprivileged_bpf_disabled = 1 # Turn on BPF JIT hardening, if the JIT is enab
by nominated1 5y ago
I’ve gone with the KSPP suggestion:
# Turn off unprivileged eBPF access.
kernel.unprivileged_bpf_disabled = 1
# Turn on BPF JIT hardening, if the JIT is enabled.
net.core.bpf_jit_harden = 2
https://kernsec.org/wiki/index.php/Kernel_Self_Protection_Project/Recommended_Settings#sysctls https://kernsec.org/wiki/index.php/Kernel_Self_Protection_Pr...