linux:apps:kvm:kvm-hardening
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| linux:apps:kvm:kvm-hardening [2026/09/13 15:03] – [Network containing] oscar | linux:apps:kvm:kvm-hardening [2026/09/16 16:31] (current) – [Network containing] oscar | ||
|---|---|---|---|
| Line 67: | Line 67: | ||
| ------------------------------------------------------- | ------------------------------------------------------- | ||
| - | !/bin/bash | + | #!/bin/bash |
| set -euo pipefail | set -euo pipefail | ||
| - | VM_NAME=" | + | NFT="/ |
| - | VM_MAC=" | + | VM_NAME=" |
| + | VM_MAC=$(/ | ||
| LIBVIRT_BRIDGE=" | LIBVIRT_BRIDGE=" | ||
| - | ALLOWED_IPV4=" | + | HOST_INTERFACE="enp2s0" |
| - | + | BLOCKED_IPV4_RANGES=" | |
| - | NFT="/usr/sbin/nft" | + | BLOCKED_IPV6_RANGES="{ 2001: |
| TABLE=" | TABLE=" | ||
| CHAIN=" | CHAIN=" | ||
| Line 86: | Line 85: | ||
| " | " | ||
| " | " | ||
| - | " | + | " |
| - | | + | |
| + | # Allow established and related return traffic | ||
| + | " | ||
| # Allow only VM -> 192.168.178.1 | # Allow only VM -> 192.168.178.1 | ||
| - | | + | " |
| - | iifname | + | " |
| - | ether saddr " | + | |
| - | ip daddr "$ALLOWED_IPV4" | + | |
| - | accept | + | |
| - | # Drop everything else originating | + | # ALLOW remaining traffic |
| - | # This includes IPv4 and IPv6. | + | " |
| - | " | + | |
| - | iifname " | + | |
| - | | + | |
| - | drop | + | |
| } | } | ||
| + | |||
| remove_rules() | remove_rules() | ||
| { | { | ||
| Line 137: | Line 132: | ||
| Check if the firewall settings are created and removed with: | Check if the firewall settings are created and removed with: | ||
| # nft list ruleset | # nft list ruleset | ||
| + | The firewall settings will look something like: | ||
| + | ``` | ||
| + | table inet vm_filter { | ||
| + | chain vm_Debian13_ESP { | ||
| + | type filter hook forward priority raw; policy accept; | ||
| + | ct state established, | ||
| + | ether saddr 51: | ||
| + | ether saddr 51: | ||
| + | ether saddr 51: | ||
| + | } | ||
| + | } | ||
| + | ``` | ||
| + | |||
| + | ## Kernel Samepage Merging (KSM) | ||
| + | In Linux, KSM (Kernel Samepage Merging) is a feature that scans your system' | ||
| + | |||
| + | * The ksm service controls the actual raw kernel thread (ksmd) that does the heavy lifting. | ||
| + | * The ksmtuned service is a user-space daemon. It actively watches your system and dynamically adjusts the tuning parameters of the kernel thread (like how fast it scans memory) based on how many QEMU/KVM instances are currently running. | ||
| + | |||
| + | #### The Security Risk: Side-Channel Attacks | ||
| + | While KSM is great for saving RAM on high-density servers, it introduces a major security flaw called a Memory Side-Channel / Cache-Leak Attack. [1, 2] | ||
| + | Because memory pages are shared between the host and the guest, a malicious process inside your Debian guest can perform precise timing measurements on memory access. By deliberately modifying a page and measuring how long it takes to process, the guest can figure out if that same data exists elsewhere in the host system' | ||
| + | |||
| + | Even if you only run a single Debian guest, KSM can still merge identical pages between your one guest and the Debian host operating system. If ksmtuned kicks in and starts aggressive page merging, the side-channel attack vector remains open between your isolated guest and your underlying hypervisor. | ||
| + | |||
| + | #### Check if KSM is running | ||
| + | To check if ksmtuned and the underlying Kernel Samepage Merging (KSM) engine are active on your Debian Trixie host, run these diagnostic commands: | ||
| + | systemctl status ksmtuned ksm | ||
| + | |||
| + | What to look for: If it says Active: active (running), it is active. If it says Active: inactive (dead) or loaded (...; masked), it is successfully disabled. | ||
| + | |||
| + | #### How to completely disable KSM | ||
| + | To ensure no memory deduplication happens at all, you should permanently stop and disable both the tuning daemon and the kernel driver: [5] | ||
| + | |||
| + | 1. Stop and mask the services so they can never be started by other system triggers: | ||
| + | |||
| + | sudo systemctl disable --now ksm ksmtuned | ||
| + | sudo systemctl mask ksm ksmtuned | ||
| + | |||
| + | 2. Force the kernel to instantly unshare any pages it has already merged: | ||
| + | |||
| + | echo 2 | sudo tee / | ||
| + | |||
| + | (Setting this to 2 completely disables the engine and forces the kernel to unmerge everything immediately. Setting it to 0 only stops it from scanning new pages). [2, 5] | ||
linux/apps/kvm/kvm-hardening.1789311838.txt.gz · Last modified: by oscar
