Zero-Downtime Linux Kernel Zero-Day Defense: Layered Compensating Controls via eBPF Telemetry, Module Disarmament, and User Namespaces
Summary
The article outlines a defense-in-depth framework to mitigate Linux kernel zero-days using eBPF telemetry, module disarmament, and user namespaces, addressing the patch gap between weaponization and upstream fixes. It covers three CVEs with a multi-layer architecture and provides practical steps, telemetry, and automation for detection and containment.