]> git.proxmox.com Git - mirror_ubuntu-kernels.git/commit
ima: force signature verification when CONFIG_KEXEC_SIG is configured
authorCoiby Xu <coxu@redhat.com>
Wed, 13 Jul 2022 07:21:11 +0000 (15:21 +0800)
committerMimi Zohar <zohar@linux.ibm.com>
Wed, 13 Jul 2022 14:13:41 +0000 (10:13 -0400)
commitaf16df54b89dee72df253abc5e7b5e8a6d16c11c
treed236aeb2c9b99d9e452b6382f016d3e1bc92fc8f
parentd2ee2cfc4aa85ff6a2a3b198a3a524ec54e3d999
ima: force signature verification when CONFIG_KEXEC_SIG is configured

Currently, an unsigned kernel could be kexec'ed when IMA arch specific
policy is configured unless lockdown is enabled. Enforce kernel
signature verification check in the kexec_file_load syscall when IMA
arch specific policy is configured.

Fixes: 99d5cadfde2b ("kexec_file: split KEXEC_VERIFY_SIG into KEXEC_SIG and KEXEC_SIG_FORCE")
Reported-and-suggested-by: Mimi Zohar <zohar@linux.ibm.com>
Signed-off-by: Coiby Xu <coxu@redhat.com>
Signed-off-by: Mimi Zohar <zohar@linux.ibm.com>
include/linux/kexec.h
kernel/kexec_file.c
security/integrity/ima/ima_efi.c