[grsec] CONFIG_PAX_KERNEXEC needs userspace protection?

Carlos Carvalho carlos at fisica.ufpr.br
Sun Jun 29 20:57:59 EDT 2008


In trying to compile 2.6.25.9 I couldn't use CONFIG_PAX_KERNEXEC
because it needs CONFIG_PAX_NOEXEC, which in turn needs either
CONFIG_PAX_PAGEEXEC or CONFIG_PAX_SEGMEXEC. I find it strange that one
cannot chose noexec protection for the kernel without activating it
for userspace as well. This didn't happen before.

Is it possible to have CONFIG_PAX_NOEXEC and CONFIG_PAX_KERNEXEC only
again?


More information about the grsecurity mailing list