Re: [gentoo-hardened] Policies and Ports - how to define access?

2016-12-04 Thread Robert Sharp
On 03/12/16 10:16, Sven Vermeulen wrote: On Fri, Dec 02, 2016 at 12:05:50PM +, Robert Sharp wrote: Mongo uses tcp on port 27017 and there is nothing defined for this in the core policy. There is a mongodb policy in contrib but it uses corenet_all_recvfrom_unlabeled,

[gentoo-hardened] Any hardened features to protect from CVE-2016–5195 like vulnerabilities?

2016-12-04 Thread Andrew Savchenko
Hi all, I'd like to know is there any way to protect from kernel vulnerabilities like CVE-2016–5195 (mad COW) using hardened technologies. (I'm not talking about how to fix this exact CVE, but how to protect from similar failures in future.) Based on exploit published I can think of the