On Fri, Jul 13, 2018 at 11:05 AM, Mimi Zohar <zo...@linux.vnet.ibm.com> wrote: > The original kexec_load syscall can not verify file signatures, nor can > the kexec image be measured. Based on policy, deny the kexec_load > syscall. > > Signed-off-by: Mimi Zohar <zo...@linux.vnet.ibm.com> > Cc: Eric Biederman <ebied...@xmission.com> > Cc: Kees Cook <keesc...@chromium.org>
Reviewed-by: Kees Cook <keesc...@chromium.org> -Kees -- Kees Cook Pixel Security _______________________________________________ kexec mailing list kexec@lists.infradead.org http://lists.infradead.org/mailman/listinfo/kexec