Re: [PATCH net 1/1] net: use random salt for netdev name hash to prevent text base leak
From: Linus Torvalds
Date: Fri Oct 02 2026 - 11:53:53 EST
On Fri, 2 Oct 2026 at 01:20, Eric Dumazet <edumazet@xxxxxxxxxx> wrote:
>
> CC Linus.
>
> It seems this patch should target net-next, local KASLR attacks are
> not a serious concern.
Correct: local KASLR on its own is pretty much a nothing-burger. Most
hardware effectively gives it to people one way or another through
timing channels in ways we can't really fix. So KASLR is really only
just "some bits of randomness against remote attackers", nothing more.
And yes, filename name hashing shouldn't use anything really secret -
the filename hash is much too simple and fundmanetally cannot be a
secure hash - that typically you shouldn't use any *real* secret
hashes for it. Using a NULL hash is not uncommon and typically better
than using something you actually want to protect.
I think the most common use of salt is the dentry pointer of the
parent dentry pointer. Which isn't great either, in how it exposes
bits of a kernel pointer, but it basically ends up being similar to
KASLR: at some point, local kernel pointer values typically *are*
something you can probe with some time and effort with timing attacks.
We try to not expose it willy-nilly, but if somebody spends the
effort, they can do cache and TLB probing and it's not "cryptographic
security" and never will be.
So yes, don't use anything you wan tto keep *really* secret as the
name hash seed.
Linus