Skip to content

ANSSI-BP-028 (high)

Rules and Groups employed by this XCCDF Profile

  • Enable poison of pages after freeing

    Fill the pages with poison patterns after free_pages() and verify the patterns before alloc_pages. This does have a potential performance impact if...
    Rule Medium Severity
  • Perform full reference count validation

    Enabling this switches the refcounting infrastructure from a fast unchecked atomic_t implementation to a fully state checked implementation, which ...
    Rule Medium Severity
  • Detect stack corruption on calls to schedule()

    This option checks for a stack overrun on calls to schedule(). If the stack end location is found to be overwritten always panic as the content of ...
    Rule Medium Severity
  • Harden slab freelist metadata

    This feature protects integrity of the allocator's metadata. This configuration is available from kernel 4.14. The configuration that was used to ...
    Rule Medium Severity
  • Randomize slab freelist

    Randomizes the freelist order used on creating new pages. This configuration is available from kernel 5.9, but may be available if backported by di...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules