Conversation

Eloy. 🔜 GPN24

Edited 4 days ago

new Linux LPE, this time using io_uring. I think it's good to point out this Google security blog from 2023. Sending all kernel commits into an LLM might be somewhat new, the mitigation measures are already old.

also I think io_uring is a very cool technology, it just has it's tradeoffs like everything. That's all :)

4
3
0

@eloy Another one? Again?

Can we just, y'know, have a break?

(I mean, I'm just going to ignore this for my personal stuff and just, well, see whatever happens or not. But I very much do not wish to be professional sysadmin right now, or possibly ever again)

0
0
0

also funny to realize that the main engineer behind io_uring is Jens Axboe, a software engineer employed at Meta. I wonder how intensely they use it in production there

0
0
0

@eloy I love io-uring, stop breaking io-uring frogangry

0
0
0

@eloy they forgot the -o in the first gcc invocation in the README (cd pintheft && gcc exp poc.c && ./exp)

0
0
1

@eloy for statistics on the distribution of areas where bugs are found, it does not really differ who (humans, LLMs or other tooling) finds it, right?

https://en.wikipedia.org/wiki/Io_uring#Security

0
0
0