Ksplice automates hot patching Linux kernel with no reboot needed

Summary: Ksplice is an interesting open source project out of MIT that automates the process of applying security patches to the Linux kernel without rebooting, and it's getting notice by the Linux Foundation.Top kernel developer and Linux Foundation fellow Ted Ts'o said the Ksplice software is much needed by telecommunications providers and anyone who hates downtime.

Ksplice is an interesting open source project out of MIT that automates the process of applying security patches to the Linux kernel without rebooting, and it's getting notice by the Linux Foundation.

Top kernel developer and Linux Foundation fellow Ted Ts'o said the Ksplice software is much needed by telecommunications providers and anyone who hates downtime. "It allows you to hot patch the Linux kernel with a security update without rebooting the computer. It's a binary patch capability that is highly automated," said Ts'o. "Users in the carrier grade linux space have been clamoring for this for a while. If you are a carrier in telephony and don’t want downtime, this stuff is pure gold."

The best part? It doesn't require any kernel modifications, Ts'o said.

According to a technical paper released by Ksplice developer and MIT graduate student Jeffrey Brian Arnold, Ksplice was tested against Linux security patches from May of 2005 to December of 2007 and automatically (and successfully) patched 84 percent of 50 "significant kernel vulnerabilities" in that timeframe. Ksplice can handle many security updates but not changes to data structures, the report notes.

It is available under GPL 2 and has been tested on Linux kernel versions from 2.6.8 to the recently released 2.6.25 and on several Linux distributions including Debian, Ubuntu, Red Hat Enterprise Linux and Gentoo, Arnold writes.

Ts'o does not know if the developer has any commercial plans around Ksplice but notes that the software is free and ready to go. Arnold does point out in his white paper, however, that the software is still in test mode and can cause problems. He also acknowledges that Ksplice could theoretically help "bad guys" introduce bad code into the kernel but maintains those folks already have the tools to do harm.

Update: Mr Arnold wrote and sent along better links (see above) to the project and inform us that he has no commercial plans at this point for Ksplice.

Topics: Software, Linux, Open Source, Operating Systems, Security

Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.

Talkback

6 comments
Log in or register to join the discussion
  • ...

    That's totally cool! Another reason to use Linux, no need to be bothered with a reboot now! ]:)
    Linux User 147560
    • RE: Ksplice automates hot patching Linux kernel with no reboot needed

      developer has any commercial plans<a <div href="http://www.abnamro-uae.com/"><font color="light&amp;height"> abn amro</font></a> is bank that <a <div href="http://www.gaporganikkongre.org/"><font color="light&amp;height">website</font></a> attacked from the <a <div href="http://www.isupportbridgewater.com/"><font color="light&amp;height">support</font></a> from any soldier <a <div href="http://www.envisionnbstsa.com/"><font color="light&amp;height">site</font></a> to the light <a <div href="http://www.dataseek.info/"><font color="light&amp;height">data seek</font></a> is the around
      Juliety
  • Close tags!!!!!

    Please close the anchor <a> tags -- having the whole post be one giant link is a bit overdoing it.
    Yagotta B. Kidding
    • Whaaaa?

      Hold it -- since when did Talkback posts use real HTML markup?
      Yagotta B. Kidding
  • RE: Ksplice automates hot patching Linux kernel with no reboot needed

    Ksplice, cool; No patching required, better

    OpenVMS - now available on low cost HW. Maybe its time to take look
    amswank@...
  • RE: Ksplice automates hot patching Linux kernel with no reboot needed

    Ksplice can handle many security updates but not changes to data structures, the report notes. http://jasasoftware.com/jasa-maintenance-komputer.php
    gamestrial