<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Kernel Security Transparency on Root Lock by HeartSuite</title><link>https://docs.heartsecsuite.com/docs/security/</link><description>Recent content in Kernel Security Transparency on Root Lock by HeartSuite</description><generator>Hugo</generator><language>en</language><atom:link href="https://docs.heartsecsuite.com/docs/security/index.xml" rel="self" type="application/rss+xml"/><item><title>Compiled-in CVEs — what each score means</title><link>https://docs.heartsecsuite.com/docs/security/compiled-in-cves/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.heartsecsuite.com/docs/security/compiled-in-cves/</guid><description>&lt;!-- Flat catalog: every entry is an h3 under the page title, so the h1-to-h3 jump is intentional. --&gt;
&lt;!-- markdownlint-disable MD001 --&gt;
&lt;p&gt;&lt;strong&gt;Overview&lt;/strong&gt;: Per-CVE write-ups for paths that exist in a Root Lock kernel. A 0.0 score means the trigger is absent on this deployment (hardware, tool, or config). A non-zero score is a live residual.&lt;/p&gt;
&lt;p&gt;Read &lt;a href="https://docs.heartsecsuite.com/docs/security/#how-to-read-the-backstop-sections"&gt;How to read the backstop sections&lt;/a&gt; on the Kernel Security Transparency landing before the entries. Compiled-out groups are on &lt;a href="../disabled-features/"&gt;Not Affected — Disabled Features&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Not Affected — disabled features</title><link>https://docs.heartsecsuite.com/docs/security/disabled-features/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.heartsecsuite.com/docs/security/disabled-features/</guid><description>&lt;!-- Flat catalog: every entry is an h3 under the page title, so the h1-to-h3 jump is intentional. --&gt;
&lt;!-- markdownlint-disable MD001 --&gt;
&lt;p&gt;&lt;strong&gt;Overview&lt;/strong&gt;: These CVE groups have no reachable code path on the Root Lock kernel because the feature is not compiled in. Confirm a gate with &lt;code&gt;grep CONFIG_&amp;lt;GATE&amp;gt; /boot/config-$(uname -r)&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Compiled-in residuals and write-ups: &lt;a href="../compiled-in-cves/"&gt;Compiled-in CVEs&lt;/a&gt;. Method: &lt;a href="https://docs.heartsecsuite.com/docs/"&gt;Kernel Security Transparency&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Root Lock is built for production servers, regulated workstations, build infrastructure, and AI agent sandboxes. The kernel does not include subsystems these workloads do not require. Each absent subsystem eliminates the full class of vulnerabilities that subsystem carries, without requiring per-CVE evaluation.&lt;/p&gt;</description></item></channel></rss>