logoalt Hacker News

staticassertionyesterday at 8:17 PM1 replyview on HN

io-uring is a security nightmare. Constant privescs and a powerful primitive for syscall smuggling. Worth considering disabling it outright (already the case for most containers afaik).


Replies

otterleyyesterday at 9:14 PM

At one point, Google disabled io_uring on its production servers (https://security.googleblog.com/2023/06/learnings-from-kctf-...) - I don't know whether this is still true, though. Perhaps a Google can confirm.

show 1 reply