summaryrefslogtreecommitdiff
path: root/drivers/usb/cdns3/cdns3-plat.c
diff options
context:
space:
mode:
authorCoiby Xu <coxu@redhat.com>2022-07-13 15:21:11 +0800
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>2022-07-21 21:24:29 +0200
commit2340428c90d43472f317125a69dace12e80927b6 (patch)
tree281e9dda1894a252498c58f7249633d14604a8fe /drivers/usb/cdns3/cdns3-plat.c
parentf4bd3202a2b4194ab6c0ce61628095d54f994db4 (diff)
ima: force signature verification when CONFIG_KEXEC_SIG is configured
[ Upstream commit af16df54b89dee72df253abc5e7b5e8a6d16c11c ] Currently, an unsigned kernel could be kexec'ed when IMA arch specific policy is configured unless lockdown is enabled. Enforce kernel signature verification check in the kexec_file_load syscall when IMA arch specific policy is configured. Fixes: 99d5cadfde2b ("kexec_file: split KEXEC_VERIFY_SIG into KEXEC_SIG and KEXEC_SIG_FORCE") Reported-and-suggested-by: Mimi Zohar <zohar@linux.ibm.com> Signed-off-by: Coiby Xu <coxu@redhat.com> Signed-off-by: Mimi Zohar <zohar@linux.ibm.com> Signed-off-by: Sasha Levin <sashal@kernel.org>
Diffstat (limited to 'drivers/usb/cdns3/cdns3-plat.c')
0 files changed, 0 insertions, 0 deletions