
Episode notes
Linux kernel maintainers are floating a proposal that would let admins disable vulnerable kernel functions at runtime. The feature is called Killswitch, and the patch was submitted in early May by Sasha Levin, a distinguished engineer at Nvidia and co-maintainer of the long-term support and stable Linux kernel trees. The Register covered it. The pitch is straightforward — when a serious vulnerability drops and patches aren't ready, instead of waiting for the build-distribute-reboot cycle, you flip a switch and the buggy function refuses to run.
The proposal arrived after a rough stretch for Linux. CopyFail (CVE-2026-31431) dropped, went from disclosure to active exploitation in days. Dirty Frag landed with public exploit code targeting the IPsec ESP and RxRPC subsystems and no official fix at the time of disclosure. The kernel community is now openly discussing whether broken functionality might be preferable to weaponized functionality. Red Hat is on record supporting the idea; the security forums are calling it "terrifying" and "absolutely ridiculous"; both reactions are defensible from where the people saying them are sitting.
The panel's argument lands somewhere close to four positions held simultaneously. The mechanism isn't new — Solaris had psradm, IBM had dynamic LPAR reconfiguration, AIX had rmdev, every generation of enterprise Unix shipped a version of "turn off the broken thing at runtime." The threat model is real but the larger threat is operational, not adversarial — the Tuesday-afternoon mis-toggle that breaks production six hours into a six-hour diagnosis is more likely than the APT using Killswitch as a defense-evasion primitive. The proposal is the right answer to the problem the kernel community is actually facing — patch pipelines cannot keep up with disclosure pipelines, and that's a structural admission worth sitting with. And the feature will be implemented badly in its first version, get an audit trail by its third, become a NIST control by its eighth, and by the time it's a NIST control nobody will remember it was supposed to be an emergency mechanism. That arc is the show.
Source Article
Linux kernel maintainers pitch emergency killswitch after CopyFail and Dirty Frag chaos - The Register, May 11, 2026
Panel
- The Legacy Sysadmin
- The Paranoid CISO
- The DBA
- The Goat Farmer's Counsel
