Gentoo Archives: gentoo-hardened

From: Matthew Thode <mthode@××××××.org>
To: gentoo-hardened@l.g.o
Subject: [gentoo-hardened] kvm on hardened (findings)
Date: Wed, 10 Nov 2010 19:02:27
Message-Id: 4CDAE9C6.2060306@mthode.org
1 Disable kernexec and uderef on host for both AMD and Intel.
2 You can enable kernexec and uderef on AMD guests.
3 You can enable kernexec but not uderef on Intel guests.
4
5 The intel processors tested were the core2duo, i3 and i7.
6
7 -- prometheanfire

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-hardened] kvm on hardened (findings) "Anthony G. Basile" <blueness@g.o>