A killswitch has been proposed for the emergency disabling of vulnerable functionality in the Linux kernel.

Sasha Levin from NVIDIA, who is responsible for maintaining the LTS branches of the Linux kernel and is a member of the advisory board of the Linux Foundation, has prepared a set of patches implementing a killswitch mechanism for the Linux kernel. This proposed feature allows for the immediate disabling of access to specific functionalities of the running kernel. It is expected that the killswitch will be useful for temporarily blocking vulnerabilities until a kernel update with a fix is installed.

The killswitch is managed through the file "/sys/kernel/security/killswitch/control", which allows intercepting calls to kernel functions by their names. For instance, to block the Copy Fail vulnerability, it is enough to write the command "engage af_alg_sendmsg -1" into the control file to enable interception of the af_alg_sendmsg function call and return an error code of "-1" instead of executing it.

Any characters supported by the kprobes subsystem can be used as names. Many recently discovered serious vulnerabilities in the kernel are present in subsystems used by a relatively small number of users (for example, AF_ALG, ksmbd, nf_tables, vsock, ax25). For most users, the inconvenience of disabling specific functions does not compare to the risk of operating the kernel with a known unpatched vulnerability until a fix is installed. The killswitch mechanism is particularly relevant in the context of today’s Dirty Frag vulnerability, for which an exploit was released before the issue was resolved in the kernel.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster