Linux Security Modules (LSM) are a framework of interfaces in the Linux kernel that lets security extensions add access-control checks at key points in kernel operations. LSM is not itself a security policy or a single product: the selected extension supplies the controls. Despite the name, an LSM extension is not an ordinary loadable kernel module.
What does LSM mean in Linux?
The Linux kernel documentation defines the purpose this way: “Linux security modules (LSM) provide a mechanism to implement additional access controls to the Linux security policies.” The framework gives extensions hooks into security-sensitive decisions; an extension uses those hooks to enforce its own rules. The framework alone does not add a policy or provide extra protection.
The term “module” can be confusing. The kernel’s Linux Security Module Usage guide says these extensions are not actually loadable kernel modules. Their availability and selection depend on kernel build options and, where supported, boot configuration.
What do Linux Security Modules do?
An LSM extension can add checks when the kernel decides whether an operation is allowed. This gives security software a way to apply controls beyond ordinary Linux discretionary access control (DAC), such as the permissions associated with files and users. Which checks apply depends on the enabled extension and its policy or rules.
Recommended Free Tools
#1 Best Overall
LSM is infrastructure, not a guarantee that a particular control is active. A system’s kernel must include and select the relevant extension, and some extensions also need userspace policy or configuration before they enforce restrictions.
Which Linux Security Modules are examples?
Linux supports multiple extensions with different purposes and policy models. The kernel documentation lists SELinux, AppArmor, Smack, and TOMOYO among the major mandatory access control (MAC) extensions. It also describes specialized components such as Yama, LoadPin, SafeSetID, Integrity Policy Enforcement (IPE), and Landlock. The exact set depends on the kernel build and boot configuration.
Rank #2
| Extension | Documented purpose or behavior |
|---|---|
| SELinux | A major MAC extension; the cited documentation does not characterize its policy model further here. |
| AppArmor | A task-centered MAC-style extension that uses profiles. A profile must be loaded from userspace for AppArmor to enforce restrictions beyond ordinary DAC permissions. |
| Smack | A major MAC extension; the cited documentation does not characterize its policy model further here. |
| TOMOYO | A major MAC extension; the cited documentation does not characterize its policy model further here. |
| Landlock | A scoped access-control and sandboxing extension that lets processes, including unprivileged ones, restrict their own ambient rights, subject to other system controls. |
This is not a ranking. These extensions address different needs, and the documentation does not establish that one is universally more secure or easier to use than another. A meaningful comparison depends on policy scope, who can define or apply rules, kernel and boot requirements, userspace tooling, interactions with other controls, and compatibility with the target kernel and distribution.
How can you see which LSMs are active?
On a system that exposes the securityfs interface, read /sys/kernel/security/lsm. It contains a comma-separated list of active LSMs. The documented ordering reflects the order in which their checks are made. The capabilities module is always included and appears first, followed by minor modules and, when configured, a major module.
The list is specific to the running system; it can differ from the extensions supported by another kernel or distribution. Kernel build and boot settings determine what is available and selected.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How does Landlock fit into LSM?
Landlock is designed for scoped sandboxing rather than replacing the system’s other access controls. The kernel documentation states, “A Landlock rule shall not interfere with other access-controls enforced on the system, only add more restrictions.” Its rules can let a process reduce its own ambient rights, including when the process is unprivileged.
Rank #4
Landlock was introduced in Linux 5.13. Using it depends on build-time and boot-time enablement, and the features available to an application depend on the running kernel’s Landlock ABI. Software should check that runtime ABI and enforce only features the kernel supports.
Quick Recap
What determines whether an LSM is available?
- Kernel build: The kernel must be built with support for the extension.
- Boot configuration: The selected LSMs may depend on boot settings supported by that kernel.
- Userspace policy: Some extensions need policy or profiles loaded from userspace; AppArmor profiles are one example.
- Kernel and distribution version: Available extensions, defaults, and features can vary. Check the target system’s kernel documentation and its live LSM list rather than assuming another system’s configuration applies.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →

