Loading…
October 8, 2026 | Prague, Czechia
View More Details & Registration  |  Note: The schedule is subject to change.
You must be registered for Linux Security Summit Europe 2026 to participate in the sessions. Please visit the event registration page to purchase a ticket. 
Thursday October 8, 2026 14:25 - 14:55 CEST
eBPF has become the backbone of modern Linux security tooling. Cilium, Tetragon, Falco, etc they all depend on eBPF's ability to hook kernel execution paths and enforce policy without a kernel patch or reboot. But there's a question the community has been slow to ask: who secures eBPF itself?
Working on bpfman, an eBPF program manager, exposed me to the trust assumptions baked into how programs get loaded, pinned, and granted kernel access. This talk covers what I found concrete attack surfaces that show up in real deployments, not theory.

We'll cover: the verifier's historical CVEs and what they reveal about its actual threat model, privilege escalation through CAP_BPF and unprivileged eBPF in distros that ship with it enabled, what program signing protects and what it quietly doesn't, and LSM hooks on BPF program loading that most teams aren't using yet.
The second half: BPF token scoping, how Ubuntu and Fedora are locking down the attack surface without breaking legitimate tooling,and a threat model checklist you can apply to your own eBPF deployment the same week.
If you're running eBPF-based security tooling in production, this is the talk I wished existed before I started.
Speakers
avatar for Hanshal Mehta

Hanshal Mehta

eBPF Engineer, Independent
Open-source developer contributing to projects across the cloud-native and security space including OpenTelemetry, bpfman, Glasskube, Cyclops, and BuildSafe. Currently at SecurableAI working on open-source security tooling. Deep interest in performance engineering, cloud security... Read More →
Thursday October 8, 2026 14:25 - 14:55 CEST
Chamber Hall

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link