Skip to content

Topic archive

Cybersecurity

Cybersecurity articles focus on practical application and infrastructure security, access controls, TLS, hardening, attack prevention, and secure operational practices.

540 articles
Cybersecurity 17 Sep 2026 5 min read

Userfaultfd Moves Page-Fault Resolution Into Userspace

Userfaultfd Moves Page-Fault Resolution Into Userspace A thread touches a registered virtual-memory page and stops before the access completes. Instead of resolving the fault entirely inside the kernel, Linux can report the event through a userfaultfd and let another userspace component decide when and with what content execution may continue. That design supports live migration, post-copy memory transfer, checkpointing, and related memory-management systems, but it also places a concurrency-sensitive decision point outside the faulting thread.

Cybersecurity 17 Sep 2026 7 min read

Unix Socket Peer Credentials Bind Identity to a Local Connection

Unix Socket Peer Credentials Bind Identity to a Local Connection A privileged local service often accepts requests from processes that share the same host but do not share the same authority. A pathname on a Unix domain socket can control who reaches the listener, yet a successful connection does not by itself tell the service which process is on the other end. Linux provides a second boundary: SO_PEERCRED lets a connected Unix socket expose peer credentials supplied by the kernel.

Cybersecurity 17 Sep 2026 7 min read

TLS Must-Staple Turns Missing OCSP Evidence Into Handshake Failure

TLS Must-Staple Turns Missing OCSP Evidence Into Handshake Failure A TLS server can hold a valid private key and present a certificate that chains to a trusted root while its revocation evidence is unavailable. Ordinary OCSP stapling does not necessarily turn that absence into failure: a client can request status information, yet the server is permitted to omit a response in the base stapling protocol. That optionality creates a security boundary. An active intermediary that can suppress access to an OCSP responder can exploit client policies that accept an inconclusive revocation check. The TLS Feature extension defined by RFC 7633 changes the certificate itself so that selected TLS features become conditions of acceptable use. For OCSP stapling, the certificate can assert that a conforming client must receive the requested status evidence.

Cybersecurity 17 Sep 2026 6 min read

TLS 1.3 Early Data Trades a Round Trip for Replay Exposure

TLS 1.3 Early Data Trades a Round Trip for Replay Exposure A returning TLS 1.3 client can possess a resumption ticket and application data ready to send before a new handshake has finished. Early data, commonly called 0-RTT data, permits those bytes to travel in the client’s first flight. The latency benefit changes a security property at exactly the point where an application may be tempted to act: early data does not carry the same replay protection as ordinary post-handshake application data.

Cybersecurity 17 Sep 2026 6 min read

Seccomp User Notification Moves Selected Syscall Decisions to a Supervisor

A confined process issues a system call that its ordinary seccomp policy cannot safely reduce to a static allow-or-deny decision. The arguments may refer to mutable process memory, or the operation may need privileged work performed outside the confined process. Returning a fixed errno is too restrictive, while permitting the call directly gives the target more authority than the deployment intends. Linux seccomp user notification creates a mediation path for this case. A filter can return SECCOMP_RET_USER_NOTIF, causing the kernel to block the triggering task and emit a request on a listener file descriptor. A userspace supervisor receives the request and later supplies a result. This mechanism changes where a selected syscall decision is made, but it does not turn seccomp into a general reference monitor without additional policy and race controls.

Cybersecurity 17 Sep 2026 7 min read

Seccomp Filters Reduce Syscall Surface Without Forming a Complete Sandbox

Seccomp Filters Reduce Syscall Surface Without Forming a Complete Sandbox A service can run with a short seccomp allowlist and still retain broad authority through file descriptors, filesystem permissions, network endpoints, and credentials. The filter may sharply reduce the kernel interfaces reachable through system calls, yet the process can remain capable of damaging actions through operations that are explicitly allowed. This is the central boundary of seccomp: it filters syscall attempts; it does not define the full security policy of a process.

Cybersecurity 17 Sep 2026 6 min read

SCM_RIGHTS Transfers File-Descriptor Authority Across Unix Sockets

SCM_RIGHTS Transfers File-Descriptor Authority Across Unix Sockets A privileged service can open a file that another process could not open by pathname, then pass that access through a Unix-domain socket. The receiving process gets a new file descriptor referring to the same kernel open-file state. No second pathname lookup is required, and the receiver’s ability to open that path is not re-evaluated as part of the transfer. That property makes SCM_RIGHTS more than an IPC convenience. It moves an already-established kernel capability across a process boundary. Security therefore depends on both sides of the exchange: the sender must constrain which descriptors can leave its authority domain, and the receiver must treat incoming descriptors as privileged objects whose properties require validation.

Cybersecurity 17 Sep 2026 6 min read

SameSite Cookies Enforce a Site Boundary, Not an Origin Boundary

SameSite Cookies Enforce a Site Boundary, Not an Origin Boundary An application at https://accounts.example.com uses a session cookie marked SameSite=Strict. A separate service at https://reports.example.com is operated by another team and has a distinct origin. The two hosts are isolated by the browser’s origin model for many web capabilities, yet a request from one can still be classified as same-site with the other. The cookie attribute is enforcing a site boundary, not duplicating the same-origin policy.

Cybersecurity 17 Sep 2026 5 min read

Pidfds Turn Process Identity Into a Stable Kernel Reference

A supervisor records PID 1842 for a worker, waits for an asynchronous event, then sends a signal. Between those operations the worker can exit, be reaped, and its numeric PID can later identify another process. The number still looks valid, but the identity it denotes has changed. Linux pidfds move this class of process control away from repeated numeric lookup. A PID file descriptor refers to a particular process, giving userspace a kernel-held reference that can be passed to interfaces such as pidfd_send_signal(), polling APIs, and, under additional permission checks, pidfd_getfd().

Cybersecurity 17 Sep 2026 5 min read

openat2 Makes Path-Resolution Policy Part of the Open

openat2 Makes Path-Resolution Policy Part of the Open A service receives a relative pathname and intends to open only objects below a directory it already trusts. A lexical check can reject obvious .. components, yet the filesystem namespace may contain symbolic links, mount points, or concurrent renames that change the path walk after that check. The security decision and the file open then describe two different moments. Linux openat2() provides a narrower boundary. Its resolve flags constrain the kernel’s path-resolution operation that produces the file descriptor. The mechanism does not make arbitrary path handling safe, but it can move several confinement rules from preflight string logic into the lookup that actually selects the object.

Cybersecurity 17 Sep 2026 5 min read

no_new_privs Makes Exec-Time Privilege Gain Irreversible

no_new_privs Makes Exec-Time Privilege Gain Irreversible A Linux service may deliberately execute programs that carry set-user-ID bits or file capabilities while intending to remain at its existing privilege level. Without an explicit execution boundary, execve() can be a privilege transition: metadata on the executable may change effective credentials or contribute capabilities to the new program. The no_new_privs task attribute changes that transition. Once set, a successful execve() cannot grant the task privilege that it could not exercise before the call. The attribute is inherited by descendants, survives execution, and cannot be cleared. Those properties make it a one-way constraint on a process lineage rather than a temporary option around one executable.

Cybersecurity 17 Sep 2026 10 min read

Mutual TLS Identity Can Disappear at a Terminating Proxy

Mutual TLS Identity Can Disappear at a Terminating Proxy A service can require a client certificate at its public endpoint, accept only certificates chained to an approved authority, and still deliver an unauthenticated request to the application behind it. The TLS check may be completely correct. The gap appears when a reverse proxy terminates that TLS connection and opens a different connection to the backend. Mutual TLS authenticates endpoints of a particular TLS connection. It does not automatically attach the authenticated client identity to HTTP requests after that connection ends, and it does not cause a second TLS connection to inherit the first connection’s peer. Once a proxy becomes the TLS server for the external client, the proxy is the component that possesses the verified client-certificate result. Any backend identity derived from that result crosses a new trust boundary.

Cybersecurity 17 Sep 2026 6 min read

Memfd Seals Turn Shared Memory Into Monotonic File Policy

Memfd Seals Turn Shared Memory Into Monotonic File Policy A process prepares a binary object in memory, passes its file descriptor to another process, and expects the bytes to remain stable after validation. Ordinary shared memory does not provide that property by itself: another holder of writable authority can change the object after a check, resize it, or keep a writable mapping alive. Linux file seals provide a narrower contract. They remove selected mutation operations from a sealable file, and successfully added seals cannot later be removed.

Cybersecurity 17 Sep 2026 7 min read

Landlock Rulesets Restrict Future Path Access, Not Open File Authority

Landlock Rulesets Restrict Future Path Access, Not Open File Authority A process opens a writable configuration file, installs a restrictive Landlock ruleset, and then continues running code that should have access only to a small working directory. The later policy can block a fresh attempt to open that configuration path, yet the descriptor obtained before confinement remains usable. The filesystem view has narrowed, but authority already materialized as an open file has not vanished.

Cybersecurity 17 Sep 2026 6 min read

Landlock Rulesets Add Process-Local Filesystem Denial Boundaries

A service starts with ordinary filesystem access inherited from its credentials, loads configuration, opens several resources, then begins processing data that may be hostile. Changing UID or entering a container can alter the surrounding authority model, but neither action by itself expresses a narrow rule such as “from this point onward, new reads are limited to these hierarchies and writes are limited to that directory.” Linux Landlock provides a process-controlled restriction layer for this boundary. A process creates a ruleset, adds object rules, and enforces the ruleset on itself. The resulting Landlock domain is stacked with existing discretionary access control and other Linux Security Module decisions. Landlock can remove access that those mechanisms would otherwise permit; it does not grant access they deny.

Cybersecurity 17 Sep 2026 8 min read

HTTP Request Smuggling Begins at a Message-Framing Disagreement

HTTP Request Smuggling Begins at a Message-Framing Disagreement A reverse proxy can validate an HTTP request, route it to an approved application, and still deliver a different request sequence from the one it believed it accepted. The failure does not require the proxy to ignore authentication or the origin to execute malformed syntax. It can arise when the two HTTP processors disagree about the byte at which one request ends and the next begins.

Cybersecurity 17 Sep 2026 7 min read

fs-verity Makes File Data Integrity a Read-Time Property

A host may need to keep independently updated executables, packages, models, or data on a writable filesystem while still detecting modification of file contents after an artifact has been accepted. A one-time userspace hash can identify the bytes at one moment, but it does not make later reads depend on that measurement. The file may be opened again, pages may be evicted and reloaded, and storage below the page cache may return different data.

Cybersecurity 17 Sep 2026 8 min read

Fetch Metadata Exposes Browser Request Context at the Server Boundary

Fetch Metadata Exposes Browser Request Context at the Server Boundary A state-changing endpoint can receive two HTTP requests with the same method, path, cookies, and body while the browser reached them through very different contexts. One may come from the application’s own document. The other may have been triggered by a foreign site through a form, image load, navigation, or another browser mechanism that permits a request without granting the initiating page access to the response.

Cybersecurity 17 Sep 2026 5 min read

execveat Binds Program Execution to an Open File Reference

A launcher selects an executable from a directory, checks attributes or content, and then starts it. If selection and execution each resolve the pathname independently, a rename, symlink change, or directory replacement between those operations can make the executed object differ from the object that was checked. Linux execveat() can move that boundary from a second pathname lookup to an already acquired file reference. With AT_EMPTY_PATH, an empty pathname tells the kernel to execute the object referred to by dirfd. That descriptor may have been opened with O_PATH. The execution decision still passes through normal kernel permission and executable-format checks, but object selection no longer depends on resolving the original pathname again.

Cybersecurity 17 Sep 2026 8 min read

Encrypted ClientHello Separates Public Routing From Private TLS Identity

Encrypted ClientHello Separates Public Routing From Private TLS Identity TLS 1.3 encrypts most handshake messages, yet a conventional connection still exposes the initial ClientHello. That message can contain Server Name Indication, allowing an on-path observer to associate a connection with a requested hostname before application traffic is protected. Encrypted ClientHello, standardized in RFC 9849, changes that boundary. The client constructs a private ClientHelloInner containing the service-specific parameters and wraps it inside a public ClientHelloOuter. The outer message remains usable by the client-facing infrastructure, while sensitive inner fields are protected with Hybrid Public Key Encryption.

Cybersecurity 17 Sep 2026 7 min read

DNS Rebinding Preserves Web Origin While Changing Network Destination

DNS Rebinding Preserves Web Origin While Changing Network Destination A browser can load active content from a public server, keep that content in the same web origin, and later send requests bearing the same hostname to a private address. No origin tuple has changed. The network destination has. That mismatch is the core of DNS rebinding. Web origins are principally identified by scheme, host, and port, while DNS maps a hostname to network addresses outside that tuple. When a name controlled by an attacker resolves differently over time, origin checks and network-location checks can describe two distinct security boundaries.

Cybersecurity 17 Sep 2026 8 min read

CSP Strict Dynamic Moves Script Trust From Host Lists to Nonce-Bearing Roots

CSP Strict Dynamic Moves Script Trust From Host Lists to Nonce-Bearing Roots A production page can have a restrictive script-src policy and still depend on a bootstrap script that creates additional script elements at runtime. A host allowlist handles that architecture by naming every permitted script origin. The list then becomes coupled to deployment topology: moving a dependency to another host can require a policy change, while admitting a broad host can authorize more executable content than the application intended.

Cybersecurity 17 Sep 2026 5 min read

Close-on-Exec Makes Descriptor Inheritance an Explicit Boundary

A service opens a privileged socket, starts helper programs, and expects those helpers to receive only standard input, output, and error. One descriptor created without close-on-exec can quietly violate that boundary. If it remains present when a new program image is installed, the helper inherits access to the kernel object even when its own credentials could never have opened that object. Linux treats this as descriptor inheritance, not a new authorization event. The security decision made when the object was opened is embodied in the descriptor. FD_CLOEXEC controls whether that established authority crosses a successful execve().

Cybersecurity 17 Sep 2026 5 min read

close_range with UNSHARE Detaches Descriptor Tables Before Bulk Closure

A multithreaded Linux process can reach an awkward boundary just before execve(): one thread wants to discard every file descriptor above standard input, output, and error, while another thread can still create descriptors in the same table. A loop of close() calls treats descriptor numbers individually, but it does not by itself change the fact that the table is shared. close_range() with CLOSE_RANGE_UNSHARE addresses that specific race. The kernel first gives the caller a file descriptor table that is no longer shared with the other users of the old table, then applies the requested bulk closure to the caller’s table. The security property is about table ownership during cleanup, not merely fewer system calls.