Fixing an old Linux process memory security bug

  Рет қаралды 9

All Systems Go!

All Systems Go!

Күн бұрын

media.ccc.de/v...
There is a well-known trade-off between security lockdowns and a user's abiliy to
debug/inspect a system. The Linux kernel is finally fixing an old proc/mem security
bug which illustrates this trade-off nicely. The kernel will provide a mechanism,
so distros need to implement a policy according to their own security needs, to
restrict proc/mem access (it gives userspace RW access to processes memory).
This talk goes into the what, why and how of getting this bug fixed, with some policies
for plugging the long-standing hole for different use-cases, without breaking
debuggers or container supervisors.
This talk is based the Linux patch series [1] which is extending the /proc/*/mem access
controls beyond the normal file-based permissions, to restrict various access during
kernel builds (Kconfig level) or early boot via static/read-only key parameters. It
is expected to land in kernel v6.11, to be released in late Q3 / early Q4 2024.
The author is looking for opinions whether this should be backported to stable trees
since the patch is somewhere between a bugfix and a new feature.
[1] patchwork.kern...
Adrian Ratiu
cfp.all-system...
#asg2024
Licensed to the public under creativecommon...

Пікірлер
Platform security in NixOS
20:56
All Systems Go!
Рет қаралды 8
Creating Arch Linux images using mkosi
25:30
All Systems Go!
Рет қаралды 4
Please Help This Superhero! 🙏
00:48
Alan Chikin Chow
Рет қаралды 7 МЛН
Electric Flying Bird with Hanging Wire Automatic for Ceiling Parrot
00:15
отомстил?
00:56
История одного вокалиста
Рет қаралды 7 МЛН
Worst flight ever
00:55
Adam W
Рет қаралды 23 МЛН
bootc: Generating an ecosystem around bootable OCI containers
43:37
An extendable and securely signed image-based OS with updates
26:50
Nerding out about Nix and NixOS with Jon Seager, Canonical
57:05
Nerding Out With Viktor
Рет қаралды 7 М.
Improving bpftrace reliability
23:07
All Systems Go!
Рет қаралды 2
Full Disk Encryption in openSUSE MicroOS and Tumbleweed
35:48
All Systems Go!
Рет қаралды 8
Waiter, an OS please, with some sysext sprinkled on top
25:26
All Systems Go!
Рет қаралды 1
bootc: Generating an ecosystem around bootable OCI containers
43:37
systemd & TPM in 2024
46:14
All Systems Go!
Рет қаралды 21
Please Help This Superhero! 🙏
00:48
Alan Chikin Chow
Рет қаралды 7 МЛН