From 340a7b97852eedaa18c8b580ba9420ee83cf382d Mon Sep 17 00:00:00 2001 From: Bastien Nocera Date: Wed, 26 Jan 2022 12:36:38 +0100 Subject: [PATCH] systemd: More lockdown bluetoothd does not need to execute mapped memory, or real-time access, so block those. --- src/bluetooth.service.in | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/src/bluetooth.service.in b/src/bluetooth.service.in index 4daedef2a..f18801866 100644 --- a/src/bluetooth.service.in +++ b/src/bluetooth.service.in @@ -22,9 +22,15 @@ ProtectControlGroups=true ReadWritePaths=@statedir@ ReadOnlyPaths=@confdir@ +# Execute Mappings +MemoryDenyWriteExecute=true + # Privilege escalation NoNewPrivileges=true +# Real-time +RestrictRealtime=true + [Install] WantedBy=bluetooth.target Alias=dbus-org.bluez.service -- 2.47.3