3 ms·
I don't know much about kernel security dev, let alone plain kernel dev, so take what I said and about to say with a (big) grain of salt. Indeed, it seems ther
by fstrthnscnd 5y ago
I don't know much about kernel security dev, let alone plain kernel dev, so take what I said and about to say with a (big) grain of salt.
Indeed, it seems there's a similar issue with traditional syscalls. I suppose that a larger attack surface means more potential vulnerabilities. The whole buffer must be considered "unsafe" by the kernel. I don't know how that structure is allocated, if it can be relocated to some other existing area to trick the kernel into doing IO there or something else.
I really don't have a clear picture of what could be done, so it might just be my paranoid sense tingling. I definitely should be more trustful wrt what's done by the kernel devs, they know their craft.