Address Space Layout Randomization (ASLR) |
![](/sites/default/files/checked-checkbox-512.png) |
* |
![](/sites/default/files/checked-checkbox-512.png) |
![](/sites/default/files/checked-checkbox-512.png) |
Base compiled as Position-Independent Executables (PIEs) |
![](/sites/default/files/checked-checkbox-512.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checked-checkbox-512.png) |
![](/sites/default/files/checked-checkbox-512.png) |
Base compiled with RELRO + BIND_NOW |
![](/sites/default/files/checked-checkbox-512.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checked-checkbox-512.png) |
* |
Ports tree compiled with PIE, RELRO, and BIND_NOW |
![](/sites/default/files/checked-checkbox-512.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checked-checkbox-512.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
Static PIE |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checked-checkbox-512.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
ASLR brute force protection (SEGVGUARD) |
* |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
* |
Prevention of the creation of writable and executable memory mappings (W^X part one) |
![](/sites/default/files/checked-checkbox-512.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checked-checkbox-512.png) |
![](/sites/default/files/checked-checkbox-512.png) |
Restrictions on mprotect to prevent switching pages between writable and executable (W^X part two) |
![](/sites/default/files/checked-checkbox-512.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checked-checkbox-512.png) |
sysctl hardening |
![](/sites/default/files/checked-checkbox-512.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
Network stack hardening (IP ID randomization, use IPv6 temporary addresses) |
![](/sites/default/files/checked-checkbox-512.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checked-checkbox-512.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
Executable file integrity enforcement |
![](/sites/default/files/checked-checkbox-512.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checked-checkbox-512.png) |
Boot hardening |
![](/sites/default/files/checked-checkbox-512.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
procfs/linprocfs hardening |
![](/sites/default/files/checked-checkbox-512.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
* |
![](/sites/default/files/checkbox-unchecked-md.png) |
LibreSSL in base as the default cryptography library |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checked-checkbox-512.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
SROP mitigation |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checked-checkbox-512.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
Most of base sandboxed |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checked-checkbox-512.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
Trusted Path Execution |
![](/sites/default/files/checked-checkbox-512.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
SafeStack in base |
![](/sites/default/files/checked-checkbox-512.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
SafeStack available in ports |
![](/sites/default/files/checked-checkbox-512.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
Non-Cross-DSO Control-Flow Integrity (CFI) in base |
![](/sites/default/files/checked-checkbox-512.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
Non-Cross-DSO Control-Flow Integrity (CFI) available in ports |
![](/sites/default/files/checked-checkbox-512.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
Base compiled with retpoline |
![](/sites/default/files/checked-checkbox-512.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checked-checkbox-512.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
Ports tree compiled with retpoline |
![](/sites/default/files/checked-checkbox-512.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
Intel SMAP+SMEP Support |
![](/sites/default/files/checked-checkbox-512.png) |
![](/sites/default/files/checked-checkbox-512.png) |
![](/sites/default/files/checked-checkbox-512.png) |
![](/sites/default/files/checked-checkbox-512.png) |
Userland stack zero-initialized by default |
![](/sites/default/files/checked-checkbox-512.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
Hardened RTLD by default |
![](/sites/default/files/checked-checkbox-512.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |
![](/sites/default/files/checkbox-unchecked-md.png) |