Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
World desk5 min

How to Check Whether Your Linux Kernel Has Security Hardening Enabled

A practical, feature-by-feature way to inspect build-time and active security protections in the Linux kernel currently running on your system.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

There is no single Linux “hardening enabled” switch. To assess the kernel that is running now, check its release and matching build configuration, then inspect runtime controls, lockdown, and boot context. Record evidence feature by feature: a build option shows capability, not necessarily that a protection is active.

1. Identify the running kernel and its configuration

Start with the release string from uname -r. Use it to locate configuration for that exact kernel; a source-tree config or one belonging to another installed kernel does not establish the running kernel’s build settings.

uname -r
ls -l "/boot/config-$(uname -r)" /proc/config.gz 2>/dev/null

On some distribution systems, the configuration is available at /boot/config-$(uname -r). Some kernels expose it through /proc/config.gz. Neither path is guaranteed to exist. Follow your distribution’s instructions if both are absent. If /proc/config.gz exists, read it with zgrep; for a readable config file, inspect selected symbols with:

grep -E '^(CONFIG_(SECURITY|STRICT_KERNEL_RWX|STRICT_MODULE_RWX|STACKPROTECTOR|RANDOMIZE_BASE|SECURITY_DMESG_RESTRICT)=|# CONFIG_(SECURITY|STRICT_KERNEL_RWX|STRICT_MODULE_RWX|STACKPROTECTOR|RANDOMIZE_BASE|SECURITY_DMESG_RESTRICT) is not set)' 
  "/boot/config-$(uname -r)"

A value of y means the option is built in; m means it is built as a module where that option supports modular builds. A line stating # CONFIG_NAME is not set indicates the option was not selected. If a symbol is missing, do not automatically call it disabled: it may be renamed, architecture-dependent, implied by another option, or absent from that kernel’s configuration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Read build-time protections as capabilities

These representative options cover different protections. Their relevance and defaults can vary by architecture, kernel release, and distribution. The Linux kernel’s self-protection documentation describes mechanisms and their tradeoffs; it does not make one fixed checklist a universal security score.

Configuration or control What it indicates What it does not establish by itself
CONFIG_STRICT_KERNEL_RWX and CONFIG_STRICT_MODULE_RWX Support for stricter memory permissions, including preventing executable kernel or module memory from also being writable and protecting read-only data. That every relevant protection is active on this architecture or that the running system has no memory-safety vulnerabilities. Defaults vary by architecture.
CONFIG_STACKPROTECTOR Build support for stack canaries, which can detect some stack buffer overflows. Protection against every overflow or proof that the kernel has no memory-corruption flaws.
CONFIG_RANDOMIZE_BASE Support for kernel base relocation used by KASLR, which probabilistically makes attacks relying on fixed kernel addresses harder. That address randomization is effective in every boot, or that it prevents attacks that do not depend on fixed addresses.
CONFIG_SECURITY_DMESG_RESTRICT A build-time setting related to the default for kernel.dmesg_restrict in Ubuntu’s documented implementation. The current sysctl value. Inspect runtime state separately and do not assume Ubuntu’s behavior is identical on other distributions.
Module signing, lockdown, and module-loading controls Distinct ways to constrain what can be loaded or how the kernel may be modified. That modules cannot be loaded merely because one related option exists. Check active policy and whether module loading is needed for the machine’s drivers or workflow.

For descriptions of the kernel’s protection goals and architecture-dependent memory-permission defaults, see the Linux kernel self-protection guide.

3. Check runtime sysctl values

Read the values currently exposed by the running system:

sysctl kernel.dmesg_restrict kernel.kptr_restrict kernel.modules_disabled

Ubuntu’s kernel protection documentation describes these controls as follows: kernel.dmesg_restrict=1 restricts kernel log access to privileged users with CAP_SYSLOG; kernel.kptr_restrict=1 restricts exposure of kernel addresses; and kernel.modules_disabled can prevent subsequent module loading. Interpret values and policy using the documentation for your own distribution and kernel.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A runtime value describes the system now; it does not prove the setting will persist across reboots. Ubuntu documents that a command-line sysctl change is non-persistent unless separately configured. If a sysctl is unavailable, report it as unavailable rather than inferring that the corresponding protection is definitely on or off.

4. Inspect lockdown, Secure Boot, and boot parameters

Read the active lockdown mode

If securityfs is mounted and the interface exists, inspect:

cat /sys/kernel/security/lockdown

The active mode is more informative than the presence of CONFIG_SECURITY_LOCKDOWN_LSM alone. The upstream lockdown Kconfig describes enabling lockdown through the kernel command line or /sys/kernel/security/lockdown. Integrity mode disables features that allow runtime modification of the kernel; confidentiality mode also restricts user-space reads of confidential kernel material. If the file or interface is absent, record that the mode could not be verified through this path.

Check Secure Boot in your distribution’s context

Use your distribution’s documented method to determine Secure Boot status, and report it separately from lockdown. Ubuntu documents lockdown enforcement tied to UEFI Secure Boot in its supported configurations, with some protections limited by architecture. These are Ubuntu-specific implementation details, not universal defaults. See Ubuntu’s security features overview and security features tables.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Record the effective kernel command line

Read the parameters passed to the currently running kernel:

cat /proc/cmdline

Note mitigation-related parameters and compare them with your distribution’s documentation. There is no one generic command-line option that proves all kernel mitigations are active; parameters can affect particular mitigations, and their meaning depends on the kernel and hardware.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

5. Report evidence, not a hardening score

Keep the result tied to the running release and distinguish build support from runtime state. A practical record can use one row per feature:

Feature Evidence checked Observed result What it supports Applicability or caveat
Kernel identity uname -r Record the exact output Identifies which running kernel the other checks concern Does not identify build options by itself
Build protections Configuration matching that release Record each symbol as y, m, not set, or unavailable Shows selected build capability or choice Symbols and defaults can depend on architecture and kernel version
Runtime sysctls sysctl output Record each value or “unavailable” Shows the value currently exposed by the running system Does not establish persistence after reboot
Lockdown and Secure Boot Lockdown interface, if present, and distribution-documented Secure Boot status Record the mode and status separately, or “not verified” Documents active lockdown state and boot context Enforcement and availability depend on distribution, platform, and architecture
Boot parameters /proc/cmdline Record relevant parameters Shows the effective command line for this boot Interpret each parameter against the kernel and distribution documentation

Linux kernel self-protection mechanisms have different scopes and can involve tradeoffs, including performance and debugging considerations. A careful report therefore says what was observed, what it demonstrates, and what remains unknown—not that the kernel is simply “secure.” These checks describe selected hardening controls; they do not certify the system against all threats.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.