A proposal called 'killswitch' for the Linux kernel aims to provide emergency short-term vulnerability mitigation by immediately disabling access to specific kernel functionality in a running system. This allows administrators to neutralize a vulnerable code path until a proper fix is available, trading temporary loss of functionality (e.g., a socket family going offline) for protection against known exploits.

1m read timeFrom lwn.net
Post cover image

Sort: