https://www.phoronix.com/news/Google-Restricting-IO_uring Phoronix * Articles & Reviews * News Archive * Forums * Premium * Categories * Computers * Display Drivers * Graphics Cards * Linux Gaming * Memory * Motherboards * Processors * Software * Storage * Operating Systems * Peripherals * Close * * Articles & Reviews * News Archive * Forums * Premium * Contact * Categories Computers Display Drivers Graphics Cards Linux Gaming Memory Motherboards Processors Software Storage Operating Systems Peripherals * [ ] [Search] Google Limiting IO_uring Use Due To Security Vulnerabilities Written by Michael Larabel in Google on 16 June 2023 at 06:07 AM EDT. 13 Comments GOOGLE While IO_uring has been one of the greatest Linux kernel innovations in recent years for helping to deliver more performant and efficient I/O, it's also been home to various security vulnerabilities. Due to ongoing security issues, this interface for asynchronous I/O is being restricted or outright disabled across Google products. The Google Security Blog noted that 60% of the submissions to the Google Vulnerability Rewards Program have been around IO_uring. Google has paid out around 1 million USD worth of IO_uring vulnerabilities from its rewards program. IO_uring exploits + rewards Google shows the massive security exposure of IO_uring in rewards costs and leading in the number of kernel exploits. As a result, Google has disabled IO_uring in Chrome OS until finding a means to properly sandbox it. Google's Android meanwhile is using a seccomp-bpf filter so that apps cannot use it while future Android releases will use SELinux to limit IO_uring to select system processes. Google is also working on disabling IO_uring by default in GKE AutoPilot. Lastly, they have disabled IO_uring use on Google production servers. The Google Security Blog went on to note: "While io_uring brings performance benefits, and promptly reacts to security issues with comprehensive security fixes (like backporting the 5.15 version to the 5.10 stable tree), it is a fairly new part of the kernel. As such, io_uring continues to be actively developed, but it is still affected by severe vulnerabilities and also provides strong exploitation primitives. For these reasons, we currently consider it safe only for use by trusted components." Read more on the Google Security Blog. 13 Comments Tweet [INS::INS] Related News Google Chrome Begins Rollout Of New "Maglev" Mid-Tier Compiler Chrome 115 Beta Brings Borderless Mode Developer Trial For Web Apps Chrome 114 Released With CHIPS, Popover API Google's Working Set Reporting Feature Aims To Better Deal With Over-Committed VMs Chrome 114 Beta Brings CSS Headline Balancing, CHIPS, Popover API Chrome 113 Released With Faster AV1 Video Encoding, WebGPU By Default About The Author Michael Larabel Michael Larabel is the principal author of Phoronix.com and founded the site in 2004 with a focus on enriching the Linux hardware experience. Michael has written more than 20,000 articles covering the state of Linux hardware support, Linux performance, graphics drivers, and other topics. Michael is also the lead developer of the Phoronix Test Suite, Phoromatic, and OpenBenchmarking.org automated benchmarking software. He can be followed via Twitter, LinkedIn, or contacted via MichaelLarabel.com. Popular News This Week Debian 12.0 Released - Powered By Linux 6.1 LTS, Easier Non-Free Firmware Handling Debian GNU/Hurd 2023 Released It's Recommended To Avoid Using The Open-Source NVIDIA Driver On Linux 6.3 Firefox 116 Should Have Experimental PipeWire Camera Support KDE Plasma 6 X11 Session "Barely Buggier" Than Plasma 5 On X11 Linux x86 Boot Process Trying To Cleanup "Hay-Wire Circuits, Duct Tape & Super Glue" Debian 13 "Trixie" Aiming To Ship With RISC-V 64-Bit Support NVIDIA 545 Linux Driver To Support Vulkan Apps With PRIME On Wayland Latest Linux News Lisa Su Reaffirms Commitment To Improving AMD ROCm Support, Engaging The Community CentOS Stream 10 Starting To Get Underway, More Activity In 2024 Linux 6.4 Lands Fix For Open-Source NVIDIA Driver Use-After-Free Issue Distrobox 1.5 Released With NVIDIA GPU Containers Support Plasma 6.0 Development Continues, More Plasma Wayland Fixes Land Python 3.13 Aiming For More Performance Firefox 116 Should Have Experimental PipeWire Camera Support Vulkan 1.3.254 Published With Another Extension Drafted By Valve AMD Prepares Linux Driver For New Feature: FreeSync Panel Replay NsCDE 2.3 Released For Modern Desktop Looking Like The Old CDE Show Your Support, Go Premium Phoronix Premium allows ad-free access to the site, multi-page articles on a single page, and other features while supporting this site's continued operations. Latest Featured Articles GNOME Wayland vs. X.Org Performance For Radeon & NVIDIA Gaming On Ubuntu 23.04 Running Linux On The ASUS ROG Ally Gaming Handheld AMD Announces Ryzen PRO 7000 Series Laptop & Desktop CPUs Intel Xeon Ice Lake vs. AMD EPYC Milan Server Performance, Efficiency & Value In 2023 RADV+Zink vs. RadeonSI OpenGL Performance On Mesa 23.2-devel Support Phoronix The mission at Phoronix since 2004 has centered around enriching the Linux hardware experience. In addition to supporting our site through advertisements, you can help by subscribing to Phoronix Premium. You can also contribute to Phoronix through a PayPal tip or tip via Stripe. Phoronix Media --------------------------------------------------------------------- * Contact * Michael Larabel * OpenBenchmarking.org Phoronix Premium --------------------------------------------------------------------- * Support Phoronix * While Having Ad-Free Browsing, * Single-Page Article Viewing Share --------------------------------------------------------------------- * Facebook * Twitter * Legal Disclaimer, Privacy Policy, Cookies | Contact * Copyright (c) 2004 - 2023 by Phoronix Media. * All trademarks used are properties of their respective owners. All rights reserved.