Kees Cook on Linux kernel 4.17 security features

If you’re not aware, Kees does a good job about blogging on new Linux kernel features. The topic list from current blog post:

Jailhouse hypervisor
Sparc ADI
new kernel stacks cleared on fork
MAP_FIXED_NOREPLACE
pin stack limit during exec
Variable Length Array removals start

security things in Linux v4.17

 

Leave a comment