News: 0001596793

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Linux 6.19 Will Allow Enforcing IPE Security Checks On Indirectly Executed Scripts

([Linux Security] 6 Hours Ago Integrity Policy Enforcement (IPE))


Linux's [1]Integrity Policy Enforcement "IPE" module is gaining a useful addition with the in-development [2]Linux 6.19 kernel.

The Linux Integrity Policy Enforcement now honors the "AT_EXECVE_CHECK" flag so user-space interpreters can signal to the kernel to perform IPE security checks on script files before execution. This functionality with AT_EXECVE_CHECK extends IPE enforcement now to indirectly-executed scripts on the system.

The updated Linux IPE documentation further explains of the new AT_EXECVE_CHECK behavior for scripts:

"With the introduction of the AT_EXECVE_CHECK flag, interpreters can use it to signal the kernel that a script file will be executed, and request the kernel to perform LSM security checks on it.

IPE's EXECUTE operation enforcement differs between compiled executables and interpreted scripts: For compiled executables, enforcement is triggered automatically by the kernel during execve(), execveat(), mmap() and mprotect() syscalls when loading executable content. For interpreted scripts, enforcement requires explicit interpreter integration using execveat() with AT_EXECVE_CHECK flag. Unlike exec syscalls that IPE intercepts during the execution process, this mechanism needs the interpreter to take the initiative, and existing interpreters won't be automatically supported unless the signal call is added."

This security contribution from Microsoft's Linux team extends IPE enforcement to indirectly executed scripts so that trusted scripts can execute while denying untrusted scripts.

More details for those interested via the [3]IPE merge for the Linux 6.19 kernel.



[1] https://www.phoronix.com/news/Linux-6.12-IPE-LSM-Security

[2] https://www.phoronix.com/search/Linux+6.19

[3] https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c8321831480d80af01ce001bd6626fc130fd13b1



David Letterman's "Things we can be proud of as Americans":
* Greatest number of citizens who have actually boarded a UFO
* Many newspapers feature "JUMBLE"
* Hourly motel rates
* Vast majority of Elvis movies made here
* Didn't just give up right away during World War II like some
countries we could mention
* Goatees & Van Dykes thought to be worn only by weenies
* Our well-behaved golf professionals
* Fabulous babes coast to coast