| ▲ | mDyJzDPmBdG 19 hours ago | |
Isn't biggest attack surface in drivers? I expect distros to split less popular kernel modules into many separate opt-in packages at cost of default hardware support, and kernel developers to purge everything without active development team. The good old "lets leave it in tree, someone might find it useful" was nice idea but that is the part that is definitely not sustainable. | ||
| ▲ | guenthert 18 hours ago | parent | next [-] | |
> Isn't biggest attack surface in drivers? That would be my guess too, the current batch however is all over the place: Bluetooth, file systems, etc. (the network layer ones are probably the most interesting ones). And the severity is mixed as well, some are 'just' vulnerabilities to potential DOS attacks. > I expect distros to split less popular kernel modules into many separate opt-in packages In the past questionable modules were blacklisted rather than removed. | ||
| ▲ | snvzz 17 hours ago | parent | prev [-] | |
Drivers run in supervisor mode as part of Linux, unfortunately. | ||