logoalt Hacker News

insanitybittoday at 2:16 AM1 replyview on HN

It's still seccomp'd off in most environments because io-uring is still a seccomp bypass that doesn't play well with kernel security systems (audit subsystem), even if it weren't also like the #1 or #2 exploit vector for privesc.


Replies

Asmod4ntoday at 5:17 AM

That’s solved as of last week, you can use cBPF now to disable functionality.

show 1 reply