Thread (13 messages) 13 messages, 3 authors, 2017-11-09

Re: [PATCH 18/27] bpf: Restrict kernel image access functions when the kernel is locked down

From: David Howells <dhowells@redhat.com>
Date: 2017-10-23 14:51:24
Also in: lkml

Alexei Starovoitov [off-list ref] wrote:
If you want to lock down read access you'd need to disable
not only bpf, but all of kprobe and likey ftrace, since
untrusted root can infer kernel data by observing function
execution even if it cannot load modules and bpf progs.
Okay.

David
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help