On 12/10/2013 10:33 AM, Vivek Goyal wrote: > On Tue, Dec 10, 2013 at 08:32:38AM -0800, H. Peter Anvin wrote: >> Of course it isn't. > > I am not sure what are you trying to say. This is too brief. > > Thanks > Vivek > Of course it is not sufficient. Once you can get arbitrary code into kernel space (CPL 0) you can do anything, and "disabling jump back" is just a speed bump. -hpa