Skip to content

Archive

Memory Isolation

1 articles
Cybersecurity 18 Sep 2026 6 min read

memfd File Seals Turn Shared Memory into a Kernel-Enforced Mutation Boundary

A broker can allocate a memory-backed object, populate it, and pass its file descriptor to another process over a UNIX domain socket. The receiver may treat the bytes as immutable configuration, compiled code, or a serialized artifact. That assumption is unsafe if the sender or another holder can still alter the same inode after validation. Linux memfd_create() and file seals provide a kernel-enforced way to narrow that mutation surface without assigning the object a persistent filesystem pathname.