Thread (52 messages) flat view 52 messages, 11 authors, 2022-01-05

Re: [PATCH V40 23/29] bpf: Restrict bpf when kernel lockdown is in confidentiality mode

From: David Howells <dhowells@redhat.com>
Date: 2019-08-30 16:33:04
Also in: linux-api, lkml, netdev

Matthew Garrett [off-list ref] wrote:
From: David Howells <dhowells@redhat.com>

bpf_read() and bpf_read_str() could potentially be abused to (eg) allow
private keys in kernel memory to be leaked. Disable them if the kernel
has been locked down in confidentiality mode.

Suggested-by: Alexei Starovoitov <redacted>
Signed-off-by: Matthew Garrett <redacted>
Reviewed-by: Kees Cook <redacted>
cc: netdev@vger.kernel.org
cc: Chun-Yi Lee <jlee@suse.com>
cc: Alexei Starovoitov <redacted>
Cc: Daniel Borkmann <daniel@iogearbox.net>
Signed-off-by: James Morris <jmorris@namei.org>
Signed-off-by: David Howells <dhowells@redhat.com>
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help