4 ms·
Is there any information available about whether the Linux KPTI patch mitigates the ability to use eBPF to read kernel memory? I'm asking because eBPF seems to
by Pyxl101 9y ago
Is there any information available about whether the Linux KPTI patch mitigates the ability to use eBPF to read kernel memory?
I'm asking because eBPF seems to execute within the kernel, and KPTI seemed to be about unmapping kernel page table when userspace processes execute.
Are there any mitigations to the eBPF attack vector?
- deleted 9y ago[deleted]
- brendangregg 9y agosysctl -w kernel.unprivileged_bpf_disabled=1 I use eBPF all the time, but I never use it as non-root, so I haven't needed unprivileged bpf anyway. update: that eBPF vector was already fixed, and another safety measure is already being considered https://lkml.org/lkml/2018/1/3/895 https://lkml.org/lkml/2018/1/3/895