@lanodan@queer.hacktivis.me @chjara@akko.wtf There are many well-known mitigation techniques, like memory poisoning, and have already existed for 10+ years. But many are very aggressive (to them, Linux is exploitable despite some mitigations because they're too half-assed). Meanwhile kernel developers don't like them and think they're either too invasive or too paranoid (e.g. In PaX, you must call pax_open_kernel() whenever you need to change a critical kernel data structure). Linus in particular, hates security people and think they're mostly impractical jerks.