Linux Kexec Restrictions & Hardening Architecture
Userspace / Root CAP_SYS_BOOT kexec_load syscall Syscall Dispatcher sys_kexec_load (raw) sys_kexec_file_load Security Latch kexec_load_disabled State: 0 (Enabled) BLOCKED (-EPERM) Execution halted Verification Engine Kernel Lockdown LSM PKCS#7 System Keyring Kexec Kernel Boot machine_kexec() handover
VULNERABLE Step: 0 / 4
Select a scenario above to observe kexec restriction and verification flow.
Security Insight: Raw kexec_load enables an attacker with CAP_SYS_BOOT to overwrite kernel code memory without signature validation.