Get the latest tech news
Memory Sealing "mseal" System Call Merged For Linux 6.10
Merged this Friday evening into the Linux 6.10 kernel is the new mseal() system call for memory sealing.
Try it today to view our site ad-free, multi-page articles on a single page, and more while the proceeds allow us to write more Linux hardware reviews. For example, such an attacker primitive can break control-flow integrity guarantees since read-only memory that is supposed to be trusted can become writable or .text pages can get remapped. The mseal system call is designed to be used by the likes of the GNU C Library "glibc" while loading ELF executables to seal non-writable memory segments or by the Google Chrome web browser and other browsers for protecting security sensitive data structures.
Or read this on Phoronix