Linux sysadmin releases ModuleJail kernel hardening script (opens in new tab)
A Belgian Linux sysadmin identified by Slashdot as Jasper Nuyens has released ModuleJail, a GPLv3 shell script intended to automatically blacklist unused Linux kernel modules after recent privilege-escalation vulnerabilities referred to as “Copy Fail” and “Dirty Frag”. Slashdot said the tool scans a running system and was written to avoid manually blacklisting dozens or hundreds of obscure modules across large Linux fleets. Openwall’s oss-security list discussed recent kernel exploits and an ...
Read the original article