Any hardened features to protect from CVE-2016–5 195 like vulnerabilities?
Andrew Savchenko <[email protected]> Mon, 5 Dec 2016 09:39:44 +0300
| Newsgroups | gmane.linux.gentoo.hardened |
|---|---|
| Message-ID | <[email protected]> |
Hi all, I'd like to know is there any way to protect from kernel vulnerabilities like CVE-2016–5195 (mad COW) using hardened technologies. (I'm not talking about how to fix this exact CVE, but how to protect from similar failures in future.) Based on exploit published I can think of the following approaches: 1) Exploit runs enormous amounts of madvise() calls, any way to rate limit it or block after some threshold is reached? I doubt there is any legitimate use case for calling madvise() that often. 2) Exploits uses huge rate of write() calls and most the fails due to access restrictions. This is definitely suspicious. Can such behaviour be spotted and blocked by some security feature? 3) Can some hardware features like Intel TSX be used to protect from such race conditions? Best regards, Andrew Savchenko
signature.asc
(application/pgp-signature, 819 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAEBCgAGBQJYRQuwAAoJEPZTWjO6HuSN3R0QAJDa5vKD5WoBOqa/w0e2KHq4 ZrDjpYFL0OZLcx+4nPU+WldeLlaDf9o3EKhKALfCIhKEQ4o4TsXUfFVcgkHcZ7Nz FG4B1Ig6bD45MVyxk5T2LO+XQisVb0W760ZqfxrqZFaM8dt5KiQrzrYxpTho7YlX XEUhpWOYk/52oj9zMNknexZXwoZYhvnCp/+2R84JNirINT+2hptVhpskOb++2Kg3 xPJTWAOcULE2KvINlRGekOwi4eWe4PkkWydsThpP1A7moo4KI2MJiJUqq3LJe8N7 qurIsjsXXwpTV2huVzgnAmfZ9g6fBJIVGeDS2frGKBJmTWTI2o/0vaMTpV10vJ7t yyWEtU5EAfMlsEiV4ag8/cC3IGFJPzIR/G5t56dxgWycr6vI1qBO28LXDNTGLnpa IhIvurXY3wZcKH1pWKZIgAI23WOpAWIa5rO7cy2iI7aEZgQTfQ3g6h+pR4MR0h88 LBDobDwZI9MFaRkypB71Wmm4mkk54IVh+0u84Fv1hPkyx3SteEsfp207PNAE9oGr ZpwR2sGvl5jpf5UVnLqxPCCNvmlBhVAhbSaWyt+senC44W3SBGVG4b0julY/Drco qjtOVd9+aaMhPE1hdoCQNBZnYou9p4Hml2J+U1LO74zhKCLMXdqjbGtcXByJurFZ q6yb/nrD3u7JfaZmaO57 =h7gV -----END PGP SIGNATURE-----