Sign in

grsecurity

@grsecurity.bsky.social
244 followers 2 following 35 posts

Foundational security for the Linux kernel. Solving the most difficult memory unsafety problems. Created by @opensrcsec

PostsRepliesMedia
grsecurity @grsecurity.bsky.social · 01/07/2026
KERNSEAL makes the linear page cache overflow in cyberstan.co.uk/fuse-readdir... deterministically unexploitable. Serial log below 👇
Serial log showing KERNSEAL preventing a linear page cache overflow in fuse_add_dirent_to_cache inlined into fuse_emit.
000
grsecurity @grsecurity.bsky.social · 23/05/2025
Nice demo: tested a vulnerable Ubuntu 22.04 system for glibc CVE-2025-4802 using Solar Designer's PoC adapted to Ubuntu (replace any occurrence of "myhostname" with "mdns4_minimal"). Even an old #grsecurity 5.4.96 kernel from February 8 2021 prevented exploitation
000
grsecurity @grsecurity.bsky.social · 05/11/2024
We need to post a correction to yesterday's eBPF performance numbers: Mathias Krause wasn't happy with just a 30x speedup and took a look at one final bottleneck that was bothering him. The speedup over vanilla is now 747x 🤯 (5.27s vs 1h5m40s)
010
grsecurity @grsecurity.bsky.social · 04/11/2024
Performance isn't the enemy of security: we care about both. Today's patches finish off a set of security/performance improvements to eBPF. Below we show a ~30x speedup vs vanilla in running the eBPF selftests with every single #grsecurity option enabled!
110