Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security][8.18] Document enhanced Linux process command line visibility #275

Open
benironside opened this issue Feb 1, 2025 · 1 comment
Assignees
Labels
documentation Improvements or additions to documentation enhancement New feature or request Team: Security

Comments

@benironside
Copy link
Contributor

Description

On Linux systems with kernel versions below 5.10.16 (basically the systems that leverage kprobe for instrumentation), process command lines get cut off after 800 characters. This creates a security risk, attackers could hide malicious payloads by adding them after the 800 character limit.

We're going to change this behavior and need to document the new limits and truncation behavior.

Resources

https://github.com/elastic/security-team/issues/11339

Which documentation set does this change impact?

Elastic On-Prem and Cloud (all)

Feature differences

What release is this request related to?

8.18

Collaboration model

The documentation team

Point of contact.

Main contact: @nick-alayil

Stakeholders:

@benironside benironside self-assigned this Feb 1, 2025
@benironside benironside added documentation Improvements or additions to documentation enhancement New feature or request Team: Security labels Feb 1, 2025
@nick-alayil
Copy link

This work has been completed for 8.18. It was initially targetted for Linux, but it looks like Defend Windows team has also applied the same approach for Windows.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
documentation Improvements or additions to documentation enhancement New feature or request Team: Security
Projects
None yet
Development

No branches or pull requests

2 participants