|
|
|
|
|
by ciconia
109 days ago
|
|
> continues to be such a consistent source of bugs - many with serious security implications... just feel that io_uring is a questionable example. Are you saying this as someone with experience, or is it just a feeling? Please give examples of recent bugs in io_uring that have security implications. |
|
There's considerable difficulty these days extrapolating "real" vulnerabilities from kernel CVEs, as the kernel team quite reasonably feel that basically any bug can be a vulnerability in the right situation, but the list of vulnerabilities in io_uring over the past 12 months[2] is pretty staggering to me.
0: https://github.com/containerd/containerd/pull/9320 1: https://security.googleblog.com/2023/06/learnings-from-kctf-... 3: https://nvd.nist.gov/vuln/search#/nvd/home?offset=0&rowCount...