oss-sec mailing list archives

Re: Re: CVE-2026-31431: CopyFail: linux local privilege scalation


From: Brian May <brian () linuxpenguins xyz>
Date: Sun, 03 May 2026 07:43:56 +1000

Reid Sutherland <reid () thirddimension net> writes:

I'm assuming any thoroughly qualified platform engineer compiles the
host kernel without module support.  At least, that needs to make a
comeback, bring back applying grsec patches and make menuconfig..

Kernel modules here are good, not bad. If everything was compiled into
the kernel it would be harder to solve this sort of security issue.

In this case, it often just meant disabling the module that often wasn't
even loaded.  The only exception was if I tested the vulnerabilty before
hand :-). Even then, easy to unload the module and disable it.

But I heard some enterprise kernels came with the code compiled into the
kernel, and these required a kernel command line option and a reboot to
fix.

Of course, maybe there is the argument that only the things you need
should be enabled; but this would be a lot harder for distros to keep
everyone happy. Maybe an argument for building your own custom kernels
not relying on distro kernels.
-- 
Brian May @ Linux Penguins


Current thread: