this post was submitted on 18 Apr 2025
7 points (88.9% liked)
Void Linux
57 readers
1 users here now
The Void (Linux) distribution
Void is a general purpose operating system, based on the monolithic Linux kernel. Its package system allows you to quickly install, update and remove software; software is provided in binary packages or can be built directly from sources with the help of the XBPS source packages collection.
This community is a mirror/alternative to !voidlinux@lemmy.ml — created for wider accessibility due to federation issues.
Share updates, configs, questions, and anything Void-related here.
founded 1 week ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Is there a hardened version of void? I'm interested in hardened distributions and like that Void has a musl build, but is there any dialogue from the devs or the community in using void as a hardened server OS?
void already comes with a pretty solid, hardened kernel setup by default. some of the security features it has out of the box include full ASLR, NX protection, protected symlinks and hardlinks, randomization for kernel heap and SLAB freelists, stack protection with GCC, and a bunch of other things like restricting access to
/dev/mem
, enforcing read-only kernel and module data, and more. the default bootloader setup also includes things likeslub_debug
,page_poison
, and secure memory allocation. but the default void settings aren't hardened at 100%, because otherwise you would be using OpenBSD lol.there's also a script called
hardening.sh
in the void-packages repo. i've seen some folks trying to bring Whonix-style features (i think its name is PlagueOS) or grsecurity/PaX-like standards to Void too, but that’s a pretty big undertaking.this is the output of
checksec --kernel
on my machineThank you for the comment. Definitely looks like there's some interest in hardening Void, with that said most of the kernel protections that I see from your
checksec
output exist on my Debian system too. I will try it out in a VM then.no problem!