3 ms·
Then just disable that singular function which causes the issue instead of a whole kernel subsystem. The current release can do that.
by Asmod4n 4mo ago
Then just disable that singular function which causes the issue instead of a whole kernel subsystem. The current release can do that.
- mort96 4mo agoWhat's the singular function that has a chance of turning out to be exploitable in the future?
- Asmod4n 4mo agoWith seccomp you can disable a single syscall which might be exploitable since you didn’t get around to patch your kernel, with cBPF you can now do the same for io_uring
- mort96 4mo agoAnd which single syscall might be exploitable? I don't wanna wait until after an exploit to disable it
- Asmod4n 4mo agoNothing stops you from disabling everything you don’t need and now io_uring offers that per OP too.
- mort96 4mo agoYes, but what parts of io_uring are safe to not disable?
- Asmod4n 4mo agoI don’t get what you mean, in the past it was all or nothing, now you can disable every single operation selectively. Gotta read the usual sources to find out what you gotta disable on your machines, like you have to for every single syscall since forever.
- mort96 4mo agoI mean exactly what I said. How do I know which parts of io_uring won't have security vulnerabilities discovered in the future?