Lightweight kernel isolation with virtualization and VM functions
Vikram Narayanan, Yongzhe Huang, Gang Tan, Trent Jaeger, Anton A. Burtsev · 2020
Commodity operating systems execute core kernel subsystems in a single address space along with hundreds of dynamically loaded extensions and device drivers. Lack of isolation within the kernel implies that a vulnerability in any of the kernel subsystems or device drivers opens a way to mount a successful attack on the entire kernel.