Projects / Capability Override LSM

Capability Override LSM

The Capability Override LSM is a Linux kernel module which, when installed, gives processes running with certain (admin-configured) user or group IDs access to one or more POSIX.1e capabilities.

Tags Security Operating System Kernels Linux
Licenses GPL
Operating Systems POSIX Linux
Implementation C

Tweet this project Short link

Rss Recent releases

  • Rrelease-mid
  •  10 Oct 2004 19:05
  • Rrelease-after

Changes: The module has been fixed to handle some API changes in recent 2.6 kernels.

  • Rrelease-mid
  •  12 Dec 2003 15:06
  • Rrelease-after

Changes: SMP issues in the module have been fixed. The policy compiler now has a fairly solid warning mechanism. Support for CAP_SETPCAP was removed due to security issues.

  • Rrelease-mid
  •  07 Dec 2003 03:25
  • Rrelease-after

Changes: This version fixes a few bugs in the policy compiler, including one that caused it to have problems using the 'users' group. Symlink handling has also been much improved.

  • Rrelease-mid
  •  07 Dec 2003 03:22
  • Rrelease-after

Changes: Rule checks are done at program load rather than for each system call, so there is less overhead. The policy can specify which rules should cause audit data to be produced. The policy compiler has much better error checking. Several bugs in the module were fixed, including a memory leak, and a race that occurred when using path checks.

  • Rrelease-mid
  •  05 Dec 2003 07:00
  • Rrelease-after

Changes: Processes can now be authorized based on the path of the executable. The policy mechanism has been completely redesigned, and is significantly more flexible and powerful. Several bugs of varying severity have been fixed. The documentation now includes a short howto on configuring a policy for your site.

372562d2c5048f5f004813246f937000_thumb

Project Spotlight

XWelltris

A 2.5D Tetris-like game.

C43552fd9079085adc2645abec6f8961_thumb

Project Spotlight

SendmailAnalyzer

A Perl script reporting sendmail usage in HTML with graphs.