‘For many of these problems, the simplest mitigation is to stop calling the error function. Killswitch Provides That’: Experts Propose Linux Kernel ‘Killswitch’ Following Troubling Recent Security Issues



  • Maintainers proposed a kill mechanism to temporarily disable vulnerable kernel functions at runtime via securityfs.
  • The feature aims to mitigate high severity flaws like Copy Fail and Dirty Frag until patches arrive, although it risks system instability.
  • It is under community review and is considered an interim measure, not a substitute for proper patching.

The Linux kernel could soon get a new feature that serves as temporary protection against high-severity vulnerabilities until patches are deployed.

One of the co-maintainers of the stable Linux kernel, Sasha Levin, recently proposed a new patch that would allow system administrators to temporarily disable a vulnerable kernel feature.

Leave a Comment

Your email address will not be published. Required fields are marked *