https://twitter.com/brainsmoke/status/948561799875502080
Not good.
https://twitter.com/brainsmoke/status/948561799875502080
Not good.
That aside, I don't think KASLR would be important enough to rush KPTI like it has happened now and to even enable it by default, given its drawbacks.
I think I understand that the subtext of this thread is: can you only bypass KASLR with it, or can you read pretty much anything from kernel memory? And yeah: it sure seems like you can work out arbitrary kernel values; it's hard to think of a way this bug could work where you can figure out the symbols of specific kernel functions, but not arbitrary values in the kernel.
So if it had been a timing attack where an unmapped memory reference takes longer to fail than a memory reference with the wrong permissions, then you could scan all of the KASLR slots without actually reading back any data.
Actually reading data is a waaaaayyy bigger deal.
But, I mean: that's what that dude is doing in that tweet, is all I'm saying. :)