Linux Security Tools Bypassed by io_uring Rootkit Technique, ARMO Research Reveals
io_uring can enable full-featured rootkits to bypass traditional Linux runtime security tooling, allowing undetected command-and-control and I/O operations.
Linux malware can avoid syscall-based endpoint protection
The proof-of-concept program 'Curing' utilizes the io_uring interface in Linux to perform IO operations that traditional antivirus tools fail to monitor, exploiting a major security blind spot.