Comment General solution (Score 1) 21
I made this general solution: blacklist all modules except the obvious ones and those loaded on your specific system. ModuleJail. One script which generates one file: /etc/modprobe.d/modulejail-blacklist.conf Easy to understand and manage. GPLv3. Enjoy the upcoming kernel module security discoveries from your lazy chair while the world burns ;)
https://github.com/jnuyens/mod...