Another solution
Another solution
Posted Jan 29, 2015 11:02 UTC (Thu) by PaXTeam (guest, #24616)In reply to: Another solution by Seegras
Parent article: A crypto module loading vulnerability
this works for custom kernels, but no so much for generic distro kernels. what may help them is a mechanism that would let modules link into vmlinux at installation time (and later every time a new not-yet-used module gets loaded) so that over time a sort-of monolithic vmlinux would emerge on the user's machine (of course bugs like the one in the article wouldn't help this process).
