Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
World desk3 min

What Are Linux Security Modules (LSM)?

Linux Security Modules are kernel infrastructure for adding access controls. Learn how the framework works, which extensions use it, and where to check the active list.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Linux Security Modules (LSM) are a framework in the Linux kernel that lets security extensions add access-control checks at important kernel decision points. LSM is not itself a security policy or a single product: an enabled extension supplies the controls, while the framework provides the hooks through which they operate.

What does LSM mean in Linux?

The Linux kernel’s Linux Security Modules documentation defines LSM as a mechanism for implementing additional access controls alongside Linux security policies. In practical terms, the framework gives extensions ways to check operations involving kernel resources and decide whether to allow them.

The distinction matters: enabling the framework alone does not impose a new policy. A security extension must implement the controls, and its policy and configuration determine how restrictions work.

Are LSMs loadable kernel modules?

Despite the name, LSM extensions are not ordinary loadable kernel modules. The kernel’s LSM usage guide explains that they are selected at build time and, in supported configurations, may be overridden at boot. What is available and active therefore depends on the kernel build and boot configuration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which security systems use the LSM framework?

Examples include SELinux, AppArmor, Smack, TOMOYO and Landlock. The kernel also documents more specialized components such as Yama, LoadPin, SafeSetID and Integrity Policy Enforcement (IPE). These are not interchangeable products or policies: they have different purposes and ways of applying restrictions. The kernel’s list of LSMs describes the extensions, while the exact set available depends on the system’s kernel and configuration.

AppArmor: profile-based restrictions

AppArmor is a task-centered, mandatory-access-control-style extension that uses profiles. A profile must be loaded from userspace for AppArmor to enforce restrictions beyond the ordinary Linux discretionary access-control permissions. The kernel documentation describes this model in its AppArmor guide.

Landlock: scoped sandboxing

Landlock lets a process restrict its own ambient rights, including when the process is unprivileged, subject to other controls on the system. Its rules are additive: as the Landlock documentation puts it, “A Landlock rule shall not interfere with other access-controls enforced on the system, only add more restrictions.” Landlock was first introduced in Linux 5.13; using it depends on build-time and boot-time enablement, and applications should check the runtime ABI so they apply only features supported by the running kernel. The kernel’s Landlock documentation covers its interface and compatibility considerations.

How can you see which LSMs are active?

On a system that exposes the security filesystem, read /sys/kernel/security/lsm. It contains a comma-separated list of the active LSMs. The order reflects the order in which checks are made. The capabilities module is always included and appears first, followed by minor modules and, where configured, a major module, according to the kernel’s LSM usage guide.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How should you compare LSM implementations?

There is no universal ranking implied by the LSM framework. To decide whether an implementation fits a system or application, consider:

  • Policy model and scope: what it restricts and whether rules apply to system-wide subjects, profiles or a sandboxed process.
  • Who defines or applies policy: for example, AppArmor relies on userspace-loaded profiles, while Landlock allows a process to restrict its own rights.
  • Kernel requirements: whether the target kernel was built with the extension and whether boot configuration enables it.
  • Userspace tooling: what tools are needed to create, load or manage the policy.
  • Interactions: how its restrictions combine with other controls already enforced on the system.
  • Compatibility: whether the distribution and running kernel support the required behavior or, for Landlock, the necessary runtime ABI features.

Because kernel support and defaults vary by release and distribution, consult the target system’s kernel documentation and inspect its live LSM list before relying on a particular configuration.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.