-
Notifications
You must be signed in to change notification settings - Fork 12
Open
Description
So far I have:
- static binaries
LD_PRELOADfor SetUID/SetGID binaries- From internal documentation (Userspace live patching):
MemoryDenyWriteExecute=yesin service configuration file.
In SLES15.4 I found:auditd.serviceaugenrules.servicesystemd-journald.servicesystemd-logind.servicesystemd-udevd.serviceuuidd.service
- seccomp driver causing calls to
mprotectwithEXECflags to be blocked
(Can this be detected? Do we have a list?) - I assume SELinux or AppArmor settings?
We need to document the exceptions. Also we should provide admins with the tooling to discover such non-livepatchable processes, so they can restart them.
Metadata
Metadata
Assignees
Labels
No labels