There is no single Linux “hardening enabled” switch. To assess the kernel that is running now, check its release and matching build configuration, then inspect runtime controls, lockdown, and boot context. Record evidence feature by feature: a build option shows capability, not necessarily that a protection is active.
1. Identify the running kernel and its configuration
Start with the release string from uname -r. Use it to locate configuration for that exact kernel; a source-tree config or one belonging to another installed kernel does not establish the running kernel’s build settings.
uname -r
ls -l "/boot/config-$(uname -r)" /proc/config.gz 2>/dev/null
On some distribution systems, the configuration is available at /boot/config-$(uname -r). Some kernels expose it through /proc/config.gz. Neither path is guaranteed to exist. Follow your distribution’s instructions if both are absent. If /proc/config.gz exists, read it with zgrep; for a readable config file, inspect selected symbols with:
grep -E '^(CONFIG_(SECURITY|STRICT_KERNEL_RWX|STRICT_MODULE_RWX|STACKPROTECTOR|RANDOMIZE_BASE|SECURITY_DMESG_RESTRICT)=|# CONFIG_(SECURITY|STRICT_KERNEL_RWX|STRICT_MODULE_RWX|STACKPROTECTOR|RANDOMIZE_BASE|SECURITY_DMESG_RESTRICT) is not set)'
"/boot/config-$(uname -r)"
A value of y means the option is built in; m means it is built as a module where that option supports modular builds. A line stating # CONFIG_NAME is not set indicates the option was not selected. If a symbol is missing, do not automatically call it disabled: it may be renamed, architecture-dependent, implied by another option, or absent from that kernel’s configuration.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
2. Read build-time protections as capabilities
These representative options cover different protections. Their relevance and defaults can vary by architecture, kernel release, and distribution. The Linux kernel’s self-protection documentation describes mechanisms and their tradeoffs; it does not make one fixed checklist a universal security score.
| Configuration or control | What it indicates | What it does not establish by itself |
|---|---|---|
CONFIG_STRICT_KERNEL_RWX and CONFIG_STRICT_MODULE_RWX |
Support for stricter memory permissions, including preventing executable kernel or module memory from also being writable and protecting read-only data. | That every relevant protection is active on this architecture or that the running system has no memory-safety vulnerabilities. Defaults vary by architecture. |
CONFIG_STACKPROTECTOR |
Build support for stack canaries, which can detect some stack buffer overflows. | Protection against every overflow or proof that the kernel has no memory-corruption flaws. |
CONFIG_RANDOMIZE_BASE |
Support for kernel base relocation used by KASLR, which probabilistically makes attacks relying on fixed kernel addresses harder. | That address randomization is effective in every boot, or that it prevents attacks that do not depend on fixed addresses. |
CONFIG_SECURITY_DMESG_RESTRICT |
A build-time setting related to the default for kernel.dmesg_restrict in Ubuntu’s documented implementation. |
The current sysctl value. Inspect runtime state separately and do not assume Ubuntu’s behavior is identical on other distributions. |
| Module signing, lockdown, and module-loading controls | Distinct ways to constrain what can be loaded or how the kernel may be modified. | That modules cannot be loaded merely because one related option exists. Check active policy and whether module loading is needed for the machine’s drivers or workflow. |
For descriptions of the kernel’s protection goals and architecture-dependent memory-permission defaults, see the Linux kernel self-protection guide.
Rank #2
3. Check runtime sysctl values
Read the values currently exposed by the running system:
sysctl kernel.dmesg_restrict kernel.kptr_restrict kernel.modules_disabled
Ubuntu’s kernel protection documentation describes these controls as follows: kernel.dmesg_restrict=1 restricts kernel log access to privileged users with CAP_SYSLOG; kernel.kptr_restrict=1 restricts exposure of kernel addresses; and kernel.modules_disabled can prevent subsequent module loading. Interpret values and policy using the documentation for your own distribution and kernel.
Rank #3
A runtime value describes the system now; it does not prove the setting will persist across reboots. Ubuntu documents that a command-line sysctl change is non-persistent unless separately configured. If a sysctl is unavailable, report it as unavailable rather than inferring that the corresponding protection is definitely on or off.
4. Inspect lockdown, Secure Boot, and boot parameters
Read the active lockdown mode
If securityfs is mounted and the interface exists, inspect:
Rank #4
cat /sys/kernel/security/lockdown
The active mode is more informative than the presence of CONFIG_SECURITY_LOCKDOWN_LSM alone. The upstream lockdown Kconfig describes enabling lockdown through the kernel command line or /sys/kernel/security/lockdown. Integrity mode disables features that allow runtime modification of the kernel; confidentiality mode also restricts user-space reads of confidential kernel material. If the file or interface is absent, record that the mode could not be verified through this path.
Check Secure Boot in your distribution’s context
Use your distribution’s documented method to determine Secure Boot status, and report it separately from lockdown. Ubuntu documents lockdown enforcement tied to UEFI Secure Boot in its supported configurations, with some protections limited by architecture. These are Ubuntu-specific implementation details, not universal defaults. See Ubuntu’s security features overview and security features tables.
Recommended Free Tools
Best Value
Record the effective kernel command line
Read the parameters passed to the currently running kernel:
cat /proc/cmdline
Note mitigation-related parameters and compare them with your distribution’s documentation. There is no one generic command-line option that proves all kernel mitigations are active; parameters can affect particular mitigations, and their meaning depends on the kernel and hardware.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.5. Report evidence, not a hardening score
Keep the result tied to the running release and distinguish build support from runtime state. A practical record can use one row per feature:
| Feature | Evidence checked | Observed result | What it supports | Applicability or caveat |
|---|---|---|---|---|
| Kernel identity | uname -r |
Record the exact output | Identifies which running kernel the other checks concern | Does not identify build options by itself |
| Build protections | Configuration matching that release | Record each symbol as y, m, not set, or unavailable |
Shows selected build capability or choice | Symbols and defaults can depend on architecture and kernel version |
| Runtime sysctls | sysctl output |
Record each value or “unavailable” | Shows the value currently exposed by the running system | Does not establish persistence after reboot |
| Lockdown and Secure Boot | Lockdown interface, if present, and distribution-documented Secure Boot status | Record the mode and status separately, or “not verified” | Documents active lockdown state and boot context | Enforcement and availability depend on distribution, platform, and architecture |
| Boot parameters | /proc/cmdline |
Record relevant parameters | Shows the effective command line for this boot | Interpret each parameter against the kernel and distribution documentation |
Linux kernel self-protection mechanisms have different scopes and can involve tradeoffs, including performance and debugging considerations. A careful report therefore says what was observed, what it demonstrates, and what remains unknown—not that the kernel is simply “secure.” These checks describe selected hardening controls; they do not certify the system against all threats.
Free tools Windows power users keep installed
One-click scans. No signup required.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




