Войти в систему

Home
    - Создать дневник
    - Написать в дневник
       - Подробный режим

LJ.Rossia.org
    - Новости сайта
    - Общие настройки
    - Sitemap
    - Оплата
    - ljr-fif

Редактировать...
    - Настройки
    - Список друзей
    - Дневник
    - Картинки
    - Пароль
    - Вид дневника

Сообщества

Настроить S2

Помощь
    - Забыли пароль?
    - FAQ
    - Тех. поддержка



Пишет LWN.net ([info]syn_lwnheadline)
@ 2020-02-14 15:03:00


Previous Entry  Add to memories!  Tell a Friend!  Next Entry
[$] Keeping secrets in memfd areas
Back in November 2019, Mike Rapoport made
the case
that there is too much address-space sharing in Linux
systems. This sharing can be convenient and good for performance, but in
an era of advanced attacks and hardware vulnerabilities it also facilitates
security problems. At that time, he proposed a number of possible changes
in general terms; he has now come back with a patch
implementing a couple of address-space isolation options for the memfd mechanism. This work demonstrates the
sort of features we may be seeing, but some of the hard work has been left
for the future.


(Читать комментарии) (Добавить комментарий)