Linux Kexec Restrictions & Hardening Architecture
Toggle Theme
1. Raw kexec_load (Unrestricted)
2. Raw kexec_load + Lockdown
3. Unsigned kexec_file_load
4. Signed kexec_file_load
5. One-Way Latch Disabled
Play / Pause
Step
Reset
Userspace / Root
CAP_SYS_BOOT
kexec_load syscall
Syscall Dispatcher
sys_kexec_load (raw)
sys_kexec_file_load
Security Latch
kexec_load_disabled
State: 0 (Enabled)
BLOCKED (-EPERM)
Execution halted
Verification Engine
Kernel Lockdown LSM
PKCS#7 System Keyring
Kexec Kernel Boot
machine_kexec() handover
VULNERABLE
Step: 0 / 4
Select a scenario above to observe kexec restriction and verification flow.
Security Insight: Raw kexec_load enables an attacker with CAP_SYS_BOOT to overwrite kernel code memory without signature validation.