Re: [PATCH v12 8/8] x86: Disallow vsyscall emulation when CET is enabled

From: Dave Hansen
Date: Fri Sep 18 2020 - 15:33:13 EST


On 9/18/20 12:23 PM, Yu-cheng Yu wrote:
> Emulation of the legacy vsyscall page is required by some programs
> built before 2013. Newer programs after 2013 don't use it.
> Disable vsyscall emulation when Control-flow Enforcement (CET) is
> enabled to enhance security.

How does this "enhance security"?

What is the connection between vsyscall emulation and CET?