Skip to content

Kernel Hardening

Linux kernel security is a foundational aspect of enterprise server hardening. The kernel manages critical system resources and interfaces, making it a prime target for exploitation. Hardening the kernel involves reducing its attack surface, enforcing strict security policies, and ensuring it remains up-to-date with security patches. Below are key techniques to achieve this.


Disabling Unused Kernel Features

Reducing the kernel's attack surface by disabling unused features minimizes potential vulnerabilities. This includes removing unnecessary kernel modules, services, and configuration options.

Example: Disabling Unused Kernel Modules

Use lsmod to identify loaded modules, then unload them with modprobe -r:

# List currently loaded modules
lsmod | grep -E 'usb_storage|nfs'

# Unload a module (ensure it's not in use)
sudo modprobe -r usb_storage

Example: Customizing Kernel Configuration

Use make menuconfig or make config to disable non-essential options during kernel compilation:

# Navigate to kernel configuration
make menuconfig

# Disable unused features (e.g., 'Networking support' > 'Wireless' > 'Bluetooth')


Patching Vulnerabilities

Regularly updating the kernel and applying security patches is critical to address known vulnerabilities.

Example: Updating the Kernel

Use your distribution's package manager to install the latest kernel:

# For Red Hat-based systems
sudo dnf update kernel

# For Debian/Ubuntu systems
sudo apt update && sudo apt upgrade linux-image-generic

Example: Applying Security Patches

For critical vulnerabilities, apply patches from the Linux kernel's official repository:

# Clone the kernel source
git clone git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git

# Apply a specific patch (e.g., CVE-2023-1234)
cd linux
patch -p1 < /path/to/cve-2023-1234.patch


Enforcing Security Policies

Enabling security modules like SELinux, AppArmor, or Kernel Hardening patches (e.g., PaX, SMEP) can enforce strict access controls and mitigate exploitation vectors.

Example: Enabling SMEP and SMEPP

Add kernel parameters to /etc/default/grub to enable Supervisor Mode Execution Protection:

GRUB_CMDLINE_LINUX="... smep=1 smepretpol=1"
Update the GRUB configuration:
sudo update-grub
sudo reboot

Example: Configuring AppArmor

Create a profile to restrict kernel module loading:

# Example AppArmor profile to deny module loading
#include <abstractions/base>

/usr/sbin/modprobe {
  deny /sbin/insmod
  deny /sbin/rmmod
}
Load the profile and restart the service:
sudo aa-complain /etc/apparmor.d/usr.sbin.modprobe
sudo systemctl restart apparmor


Secure Boot and Kernel Integrity

Enabling Secure Boot ensures the kernel is signed and cannot be tampered with during boot.

Example: Verifying Kernel Signatures

Check that the kernel is signed with a trusted certificate:

sudo rpm -V kernel
# Or for Debian/Ubuntu:
sudo dpkg -s linux-image-$(uname -r)

Example: Using Shim for Secure Boot

Ensure the bootloader (Shim) is configured to validate kernel signatures:

# Verify Shim's signature (requires a trusted key)
sudo rpm --import /usr/share/keys/shim.gpg


Key takeaways

  • Disable unused kernel modules and features to reduce the attack surface.
  • Regularly update the kernel and apply security patches from trusted sources.
  • Enforce security policies using SELinux, AppArmor, or kernel hardening patches like SMEP.
  • Enable Secure Boot to ensure kernel integrity and prevent tampering.
  • Monitor and audit kernel logs for unauthorized access attempts or anomalies.