From cfe7314af156e036e3e1ef4b0853c68679de57a7 Mon Sep 17 00:00:00 2001 From: Tommy Date: Sat, 8 Jun 2024 18:02:50 -0700 Subject: [PATCH] Disable fs.binfmt_misc.status (#282) --- config/files/usr/etc/sysctl.d/hardening.conf | 1 + 1 file changed, 1 insertion(+) diff --git a/config/files/usr/etc/sysctl.d/hardening.conf b/config/files/usr/etc/sysctl.d/hardening.conf index 6724e6c..cbd3fce 100644 --- a/config/files/usr/etc/sysctl.d/hardening.conf +++ b/config/files/usr/etc/sysctl.d/hardening.conf @@ -22,6 +22,7 @@ kernel.sysrq = 0 kernel.perf_event_paranoid = 3 kernel.kptr_restrict = 2 kernel.dmesg_restrict = 1 +fs.binfmt_misc.status = 0 fs.suid_dumpable = 0 fs.protected_regular = 2 fs.protected_fifos = 2