Any hardened features to protect from CVE-2016–5 195 like vulnerabilities?

Andrew Savchenko <[email protected]> Mon, 5 Dec 2016 09:39:44 +0300
Newsgroups gmane.linux.gentoo.hardened
Message-ID <[email protected]>
Hi all,

I'd like to know is there any way to protect from kernel
vulnerabilities like CVE-2016–5195 (mad COW) using hardened
technologies. (I'm not talking about how to fix this exact CVE, but
how to protect from similar failures in future.)

Based on exploit published I can think of the following approaches:

1) Exploit runs enormous amounts of madvise() calls, any way to
rate limit it or block after some threshold is reached? I doubt
there is any legitimate use case for calling madvise() that often.

2) Exploits uses huge rate of write() calls and most the fails due
to access restrictions. This is definitely suspicious. Can such
behaviour be spotted and blocked by some security feature?

3) Can some hardware features like Intel TSX be used to protect
from such race conditions? 

Best regards,
Andrew Savchenko
signature.asc (application/pgp-signature, 819 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJYRQuwAAoJEPZTWjO6HuSN3R0QAJDa5vKD5WoBOqa/w0e2KHq4
ZrDjpYFL0OZLcx+4nPU+WldeLlaDf9o3EKhKALfCIhKEQ4o4TsXUfFVcgkHcZ7Nz
FG4B1Ig6bD45MVyxk5T2LO+XQisVb0W760ZqfxrqZFaM8dt5KiQrzrYxpTho7YlX
XEUhpWOYk/52oj9zMNknexZXwoZYhvnCp/+2R84JNirINT+2hptVhpskOb++2Kg3
xPJTWAOcULE2KvINlRGekOwi4eWe4PkkWydsThpP1A7moo4KI2MJiJUqq3LJe8N7
qurIsjsXXwpTV2huVzgnAmfZ9g6fBJIVGeDS2frGKBJmTWTI2o/0vaMTpV10vJ7t
yyWEtU5EAfMlsEiV4ag8/cC3IGFJPzIR/G5t56dxgWycr6vI1qBO28LXDNTGLnpa
IhIvurXY3wZcKH1pWKZIgAI23WOpAWIa5rO7cy2iI7aEZgQTfQ3g6h+pR4MR0h88
LBDobDwZI9MFaRkypB71Wmm4mkk54IVh+0u84Fv1hPkyx3SteEsfp207PNAE9oGr
ZpwR2sGvl5jpf5UVnLqxPCCNvmlBhVAhbSaWyt+senC44W3SBGVG4b0julY/Drco
qjtOVd9+aaMhPE1hdoCQNBZnYou9p4Hml2J+U1LO74zhKCLMXdqjbGtcXByJurFZ
q6yb/nrD3u7JfaZmaO57
=h7gV
-----END PGP SIGNATURE-----