Why not remove the code?
Why not remove the code?
Posted Dec 5, 2017 10:57 UTC (Tue) by NAR (subscriber, #1313)Parent article: Restricting automatic kernel-module loading
I'm not sure I get the attack vector here. If the problem is that there is unmaintained code in the kernel that might be loaded by the user - why not remove the unmaintained code from the kernel instead? If there are legitimate users of the user-triggered kernel module autoloading, I don't see any solution that would not break their use cases. Sufficiently paranoid system administrators could have locked down their systems already by compiling everything into the kernel and disable module loading, couldn't they?
