Linux Security Modules (LSM) are a framework in the Linux kernel that lets security extensions add access-control checks at important kernel decision points. LSM is not itself a security policy or a single product: an enabled extension supplies the controls, while the framework provides the hooks through which they operate.
What does LSM mean in Linux?
The Linux kernel’s Linux Security Modules documentation defines LSM as a mechanism for implementing additional access controls alongside Linux security policies. In practical terms, the framework gives extensions ways to check operations involving kernel resources and decide whether to allow them.
The distinction matters: enabling the framework alone does not impose a new policy. A security extension must implement the controls, and its policy and configuration determine how restrictions work.
Are LSMs loadable kernel modules?
Despite the name, LSM extensions are not ordinary loadable kernel modules. The kernel’s LSM usage guide explains that they are selected at build time and, in supported configurations, may be overridden at boot. What is available and active therefore depends on the kernel build and boot configuration.
Recommended Free Tools
#1 Best Overall
Which security systems use the LSM framework?
Examples include SELinux, AppArmor, Smack, TOMOYO and Landlock. The kernel also documents more specialized components such as Yama, LoadPin, SafeSetID and Integrity Policy Enforcement (IPE). These are not interchangeable products or policies: they have different purposes and ways of applying restrictions. The kernel’s list of LSMs describes the extensions, while the exact set available depends on the system’s kernel and configuration.
AppArmor: profile-based restrictions
AppArmor is a task-centered, mandatory-access-control-style extension that uses profiles. A profile must be loaded from userspace for AppArmor to enforce restrictions beyond the ordinary Linux discretionary access-control permissions. The kernel documentation describes this model in its AppArmor guide.
Rank #2
Landlock: scoped sandboxing
Landlock lets a process restrict its own ambient rights, including when the process is unprivileged, subject to other controls on the system. Its rules are additive: as the Landlock documentation puts it, “A Landlock rule shall not interfere with other access-controls enforced on the system, only add more restrictions.” Landlock was first introduced in Linux 5.13; using it depends on build-time and boot-time enablement, and applications should check the runtime ABI so they apply only features supported by the running kernel. The kernel’s Landlock documentation covers its interface and compatibility considerations.
How can you see which LSMs are active?
On a system that exposes the security filesystem, read /sys/kernel/security/lsm. It contains a comma-separated list of the active LSMs. The order reflects the order in which checks are made. The capabilities module is always included and appears first, followed by minor modules and, where configured, a major module, according to the kernel’s LSM usage guide.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Rank #3
How should you compare LSM implementations?
There is no universal ranking implied by the LSM framework. To decide whether an implementation fits a system or application, consider:
- Policy model and scope: what it restricts and whether rules apply to system-wide subjects, profiles or a sandboxed process.
- Who defines or applies policy: for example, AppArmor relies on userspace-loaded profiles, while Landlock allows a process to restrict its own rights.
- Kernel requirements: whether the target kernel was built with the extension and whether boot configuration enables it.
- Userspace tooling: what tools are needed to create, load or manage the policy.
- Interactions: how its restrictions combine with other controls already enforced on the system.
- Compatibility: whether the distribution and running kernel support the required behavior or, for Landlock, the necessary runtime ABI features.
Because kernel support and defaults vary by release and distribution, consult the target system’s kernel documentation and inspect its live LSM list before relying on a particular configuration.
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




