On Tue, 2022-07-12 at 17:33 +0800, Coiby Xu wrote: > Currently, an unsigned kernel could be kexec'ed when IMA arch specific > policy is configured unless lockdown is enabled. Enforce kernel > signature verification check in the kexec_file_load syscall when IMA > arch specific policy is configured. > > Fixes: 99d5cadfde2b ("kexec_file: split KEXEC_VERIFY_SIG into KEXEC_SIG and KEXEC_SIG_FORCE") > Reported-by: Mimi Zohar <zohar@xxxxxxxxxxxxx> > Suggested-by: Mimi Zohar <zohar@xxxxxxxxxxxxx> > Signed-off-by: Coiby Xu <coxu@xxxxxxxxxx> Thanks, Coiby. This patch is now queued in next-integrity/next- integrity-testing. Mimi