Sign in

grsecurity

@grsecurity.bsky.social
244 followers 2 following 35 posts

Foundational security for the Linux kernel. Solving the most difficult memory unsafety problems. Created by @opensrcsec

PostsRepliesMedia
grsecurity @grsecurity.bsky.social · 08/07/2026
If you're just now hearing about GhostLock and looking to fix it, make sure you don't introduce two unpriv-reachable DoSes associated with its fixes. The fix the Linux CNA lists for CVE-2026-43499 introduces a NULL deref, which caused CVE-2026-53166 to be issued.
110
grsecurity @grsecurity.bsky.social · 01/07/2026
KERNSEAL makes the linear page cache overflow in cyberstan.co.uk/fuse-readdir... deterministically unexploitable. Serial log below 👇
Serial log showing KERNSEAL preventing a linear page cache overflow in fuse_add_dirent_to_cache inlined into fuse_emit.
000
grsecurity @grsecurity.bsky.social · 15/05/2026
We've just published a Knowledge Base article with more information about the vulnerability, current published/unpublished exploits, and current mitigations. We still recommend patching ASAP.
010
grsecurity @grsecurity.bsky.social · 14/05/2026
Exploits are now appearing targeting pidfd, which is forced into all Linux kernels since 5.10 (2020), no module or initcall to blacklist this time, must patch ASAP!
176
grsecurity @grsecurity.bsky.social · 14/05/2026
We've just sent a mail to all customers notifying them of this issue, with split-out fixes available for 5.15, 6.6, and 6.18. We'll share more information on our Knowledge Base as it becomes available.
000
grsecurity @grsecurity.bsky.social · 14/05/2026
We've uploaded new patches for 5.15, 6.6, and 6.18 to address an obfuscated upstream Linux logic vulnerability that should exist in all kernel versions: git.kernel.org/pub/scm/linu...
101
grsecurity @grsecurity.bsky.social · 08/05/2026
We've published a detailed KB article for customers on the two vulnerabilities involved in Dirty Frag and the associated public exploits, feel free to reach out with any questions.
000
grsecurity @grsecurity.bsky.social · 30/04/2026
The KB article with links to the combined/split-out patches for 5.15 and 6.6 (adapted to grsecurity) are now available.
000
grsecurity @grsecurity.bsky.social · 30/04/2026
Updated 5.15 and 6.6 patches are now available. We're now preparing a KB article with more guidance than shared in last night's email with links to combined/split-out patches for both 5.15 and 6.6 for those on older kernels who need CONFIG_CRYPTO_USER_API_AEAD enabled (which shouldn't be anyone)
010
grsecurity @grsecurity.bsky.social · 29/04/2026
Creating a separate post so more people see this: the mitigation recommended by Theori.io for copy.fail *WILL NOT WORK* for any RHEL or RHEL-derived distro, including CentOS, Fedora, Oracle, and Alma as the vulnerable code is built-in.
123
grsecurity @grsecurity.bsky.social · 19/03/2026
Today, Mathias Krause of our team has submitted patches for the NVIDIA open gpu kernel modules that implement full Kbuild support, paving the way for CFI, KASAN/UBSAN, and our many compiler plugins. Running AI workloads with NVIDIA GPUs no longer means weakening kernel security. Links below 👇️
100
grsecurity @grsecurity.bsky.social · 28/01/2026
Our 6.18 #grsecurity LTS release, to be supported through at least the end of 2028, is now available!
000
grsecurity @grsecurity.bsky.social · 16/12/2025
Just sent out our year end wrap-up mail to customers. It's a bit bigger than usual, so grab yourself some Swiss Miss and enjoy! If you didn't receive it, but should have, just reach out and we'll make sure you're on the list. Happy holidays!
010
grsecurity @grsecurity.bsky.social · 04/12/2025
6.18 has been selected as the next #grsecurity stable kernel version, to be supported through the end of 2028, one year longer than the upstream LTS EOL date of Dec 2027.
000
grsecurity @grsecurity.bsky.social · 26/06/2025
Quick reminder that our 6.8 short-term stable kernel goes EOL at the end of this month. Some stats: over the period of a year, it included over 1500 security/stability-relevant backports.
000
grsecurity @grsecurity.bsky.social · 23/05/2025
Nice demo: tested a vulnerable Ubuntu 22.04 system for glibc CVE-2025-4802 using Solar Designer's PoC adapted to Ubuntu (replace any occurrence of "myhostname" with "mdns4_minimal"). Even an old #grsecurity 5.4.96 kernel from February 8 2021 prevented exploitation
000
grsecurity @grsecurity.bsky.social · 24/02/2025
It's now available!
000
grsecurity @grsecurity.bsky.social · 19/02/2025
We expect our 6.13 #grsecurity beta to be available within the next two weeks.
000
grsecurity @grsecurity.bsky.social · 03/02/2025
github.com/google/secur...
github.com
AMD: Microcode Signature Verification Vulnerability
### Summary Google Security Team has identified a security vulnerability in some AMD Zen-based CPUs. This vulnerability allows an adversary with local administrator privileges (ring 0 from outside...
001
grsecurity @grsecurity.bsky.social · 16/01/2025
Our 6.12 #grsecurity beta is now available to beta testers for testing
000
grsecurity @grsecurity.bsky.social · 23/12/2024
Slides for Pawel's H2HC presentation this month on the TLB are now available on grsecurity.net/papers If you've never heard of "paging-structure caches" before, check it out!
000
grsecurity @grsecurity.bsky.social · 05/11/2024
We need to post a correction to yesterday's eBPF performance numbers: Mathias Krause wasn't happy with just a 30x speedup and took a look at one final bottleneck that was bothering him. The speedup over vanilla is now 747x 🤯 (5.27s vs 1h5m40s)
010
grsecurity @grsecurity.bsky.social · 04/11/2024
Performance isn't the enemy of security: we care about both. Today's patches finish off a set of security/performance improvements to eBPF. Below we show a ~30x speedup vs vanilla in running the eBPF selftests with every single #grsecurity option enabled!
110
grsecurity @grsecurity.bsky.social · 19/10/2024
Johannes Wikner has published a detailed walkthrough of the first cross-process Spectre exploit against a real target, an attack he developed in part during his internship with us last year. Check it out here: grsecurity.net/cross_proces...
002
grsecurity @grsecurity.bsky.social · 25/09/2024
A new version of paxctld (1.2.6) is now available for download!
021