set /proc/sys/vm/mmap_min_addr to 4096
authorFaidon Liambotis <paravoid@debian.org>
Fri, 14 Aug 2009 01:24:39 +0000 (04:24 +0300)
committerPeter Palfrader <peter@palfrader.org>
Tue, 18 Aug 2009 18:45:36 +0000 (20:45 +0200)
commita1ffa958a48f4d4fd130df3fe415657cf7d5b6b4
treea394d00e0eb1c9c4cb8c6c573ff2bc4c8238f6e1
parent592759a869498488ea7227a481b3194989f6c140
set /proc/sys/vm/mmap_min_addr to 4096

This prohibits userland to mmap() page 0 and therefore mitigates
exploits that use NULL-pointer dereference vulnerabilities in the
kernel.

Introduce a sysctl puppet definition for this that can be used to set
other sysctl knobs as well.

Signed-off-by: Peter Palfrader <peter@palfrader.org>
modules/debian-org/manifests/init.pp