X-Git-Url: http://pilppa.org/gitweb/?a=blobdiff_plain;f=security%2FKconfig;h=5dfc206748cfbd76f2e1f3114515aba7294cf67c;hb=7b584163979a9fe2ebfdd57a9d64cbe27166ab70;hp=389e151e3b68e832d7b63b9623e10098d6d2e03b;hpb=6232665040f9a23fafd9d94d4ae8d5a2dc850f65;p=linux-2.6-omap-h63xx.git diff --git a/security/Kconfig b/security/Kconfig index 389e151e3b6..5dfc206748c 100644 --- a/security/Kconfig +++ b/security/Kconfig @@ -104,7 +104,26 @@ config SECURITY_ROOTPLUG If you are unsure how to answer this question, answer N. +config SECURITY_DEFAULT_MMAP_MIN_ADDR + int "Low address space to protect from user allocation" + depends on SECURITY + default 0 + help + This is the portion of low virtual memory which should be protected + from userspace allocation. Keeping a user from writing to low pages + can help reduce the impact of kernel NULL pointer bugs. + + For most users with lots of address space a value of 65536 is + reasonable and should cause no problems. Programs which use vm86 + functionality would either need additional permissions from either + the LSM or the capabilities module or have this protection disabled. + + This value can be changed after boot using the + /proc/sys/vm/mmap_min_addr tunable. + + source security/selinux/Kconfig +source security/smack/Kconfig endmenu