By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Microsoft Is Back To Working On “Hornet” Security For eBPF Programs On Linux
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Microsoft Is Back To Working On “Hornet” Security For eBPF Programs On Linux
Computing

Microsoft Is Back To Working On “Hornet” Security For eBPF Programs On Linux

News Room
Last updated: 2025/12/11 at 6:27 AM
News Room Published 11 December 2025
Share
Microsoft Is Back To Working On “Hornet” Security For eBPF Programs On Linux
SHARE

Earlier in the year Microsoft proposed the “Hornet” Linux security module to provide signature verification capabilities for eBPF programs to provide for better system security. It’s been months since hearing anything more about it and not being merged, but yesterday they “reintroduced” it to the Linux kernel community.

Blaise Boscaccy of Microsoft’s Linux team posted the latest iteration of their Hornet Linux security module for providing signature verification on eBPF programs. Their focus is on providing better security and audit integrity as well as TOCTOU attack prevention.

Microsoft Hornet

The cover letter on the new RFC patch series explains:

“This patch series introduces the next iteration of the Hornet LSM. Hornet’s goal is to provide a secure and extensible in-kernel signature verification mechanism for eBPF programs. The purpose of this RFC is to gather feedback on the LSM design and the newly added downstream LSM hooks, as well as gauge community sentiment. The userspace tooling still needs some refinement. The currently accepted loader-plus-map signature verification scheme, mandated by Alexei and KP, is simple to implement and generally acceptable if users and administrators are satisfied with it. However, verifying both the loader and the maps offers additional benefits beyond verifying the loader alone:

1. Security and Audit Integrity

A key advantage is that the LSM hook for authorizing BPF program loads can operate after signature verification. This ensures:

* Access control decisions are based on verified signature status.

* Accurate system state measurement and logging.

* Log entries claiming a verified signature are truthful, avoiding misleading records where only the loader was verified while the actual BPF program verification occurs later without logging.

2. TOCTOU Attack Prevention

The current map hash implementation may be vulnerable to a TOCTOU attack because it allows unfrozen maps to cache a previously calculated hash. The accepted “trusted loader” scheme cannot detect this and may permit loading altered maps.

This approach addresses concerns from users who require strict audit trails and verification guarantees, especially in security-sensitive environments. Map hashes for extended verification are passed via the existing PKCS#7 UAPI and verified by the crypto subsystem. Hornet then calculates the program’s verification state (full, partial, bad, etc.) and invokes a new downstream LSM hook to delegate policy decisions.”

We’ll see if Microsoft’s Hornet LSM manages to make it into the mainline Linux kernel in 2026 for providing these enhancements around eBPF programs.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Uber Eats autonomous robot couriers launch in Leeds – UKTN Uber Eats autonomous robot couriers launch in Leeds – UKTN
Next Article Today's NYT Strands Hints, Answer and Help for Dec. 11 #648 – CNET Today's NYT Strands Hints, Answer and Help for Dec. 11 #648 – CNET
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Save 20% off ‘Clair Obscur: Expedition 33’, back down to its Black Friday price
Save 20% off ‘Clair Obscur: Expedition 33’, back down to its Black Friday price
News
Starbucks China appoints Tony Yang as first CGO amid restructuring and declining sales · TechNode
Starbucks China appoints Tony Yang as first CGO amid restructuring and declining sales · TechNode
Computing
PSA: iOS 26.2 Turns on Automatic Software Updates for Some Users
PSA: iOS 26.2 Turns on Automatic Software Updates for Some Users
News
Major Leak Reveals 7 New Features Coming With iOS 26.4 – BGR
Major Leak Reveals 7 New Features Coming With iOS 26.4 – BGR
News

You Might also Like

Starbucks China appoints Tony Yang as first CGO amid restructuring and declining sales · TechNode
Computing

Starbucks China appoints Tony Yang as first CGO amid restructuring and declining sales · TechNode

2 Min Read
XREAL launches new AR glasses XREAL One with native 3DoF spatial tracking · TechNode
Computing

XREAL launches new AR glasses XREAL One with native 3DoF spatial tracking · TechNode

1 Min Read
Moonshot AI:  billion valuation overshadowed by legal dispute with 5 key investors · TechNode
Computing

Moonshot AI: $3 billion valuation overshadowed by legal dispute with 5 key investors · TechNode

7 Min Read
Xiaomi’s first SUV could go on sale alongside new foldable phones · TechNode
Computing

Xiaomi’s first SUV could go on sale alongside new foldable phones · TechNode

4 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?