4 ms·
Nothing, but that only makes reading the malware's memory possible with these exploits. That malware won't be able to access memory of some other process, if th
by binarybanana 5y ago
Nothing, but that only makes reading the malware's memory possible with these exploits. That malware won't be able to access memory of some other process, if that other process is using those flags itself.
Edit: For that to work that flag would have to work on the context switch level. So every time you switch away from a sensitive process, flush all buffers and whatever else, then switch.
This also requires the kernel itself to enable mitigations as necessary when it touches encryption keys before switching back to user space.