The long road to a fix for CVE-2021-20316
The long road to a fix for CVE-2021-20316
Posted Feb 12, 2022 2:55 UTC (Sat) by bartoc (guest, #124262)In reply to: The long road to a fix for CVE-2021-20316 by rgmoore
Parent article: The long road to a fix for CVE-2021-20316
Generally, I think linux is fine adding in (usually default to off) options that break userspace in the name of security (I could be wrong). I think something like this is worth trying out at least to see how much stuff breaks, given it could remove a whole class of toctou bugs.
My userspace was just broken by lack of `/dev/mem` on my fedora box (I was trying to fetch the EDID of my display)