Preparatory patches: github.com/NVIDIA/open-...
Full Kbuild support: github.com/NVIDIA/open-...
#grsecurity compatibility: github.com/NVIDIA/open-...
Our 6.18 #grsecurity LTS release, to be supported through at least the end of 2028, is now available!
6.18 has been selected as the next #grsecurity stable kernel version, to be supported through the end of 2028, one year longer than the upstream LTS EOL date of Dec 2027.
Nice demo: tested a vulnerable Ubuntu 22.04 system for glibc CVE-2025-4802 using Solar Designer's PoC adapted to Ubuntu (replace any occurrence of "myhostname" with "mdns4_minimal"). Even an old #grsecurity 5.4.96 kernel from February 8 2021 prevented exploitation
We expect our 6.13 #grsecurity beta to be available within the next two weeks.
Our 6.12 #grsecurity beta is now available to beta testers for testing
Performance isn't the enemy of security: we care about both. Today's patches finish off a set of security/performance improvements to eBPF. Below we show a ~30x speedup vs vanilla in running the eBPF selftests with every single #grsecurity option enabled!