hello,
i have come across https://www.linux-magazin.de/ausgaben/2017/05/kvm-security/2/ , which is telling that ksm may impose a security risk.
since it seems KSM is enabled in proxmox per default, i wonder if it's a good idea to have ksm active on a server which is hosting VMs exposed to the internet.
in https://pve.proxmox.com/wiki/Dynamic_Memory_Management , there is no hint, that ksm may impose a security risk.
nothing but hot air from security researchers, or should we care and at least add some information to the wiki, that it should better be disabled for sensible environments?
roland
i have come across https://www.linux-magazin.de/ausgaben/2017/05/kvm-security/2/ , which is telling that ksm may impose a security risk.
since it seems KSM is enabled in proxmox per default, i wonder if it's a good idea to have ksm active on a server which is hosting VMs exposed to the internet.
in https://pve.proxmox.com/wiki/Dynamic_Memory_Management , there is no hint, that ksm may impose a security risk.
nothing but hot air from security researchers, or should we care and at least add some information to the wiki, that it should better be disabled for sensible environments?
roland