logoalt Hacker News

bjackmantoday at 1:15 PM1 replyview on HN

Yeah you need native code execution, and if you have AF_ALG access there is clearly no sandboxing in place. At that point it's game over on Linux, there are too many bugs. Even if you fix all the known ones in the current kernel, by the time the version with those fixes is qualified and released (not to mention, the machine must reboot), new LPEs have been discovered.


Replies

eggpricestoday at 4:35 PM

To convince me Linux is full of kernel LPE bugs, can you share some of the bugs?

show 1 reply