Google's Kage Project Rethinks Linux Kernel Security With Isolated Device Drivers
by George Whittaker Google is exploring a new approach to Linux kernel security that could significantly change how device drivers interact with the operating system. The experimental project, known as Kage, uses compiler-based sandboxing to isolate drivers inside the kernel, potentially limiting the damage caused by memory corruption, programming errors, and exploitable vulnerabilities without requiring drivers to run as separate user-space processes. The research was presented at the Linux Plumbers Conference 2026, held October 5–7, with Stanford University and Google researcher Zachary Yedidia discussing how LLVM's Lightweight Fault Isolation (LFI) technology can create restricted execution environments for native kernel code. Unlike conventional isolation techniques, which often depend on separate processes or virtual machines, Kage attempts to preserve the performance advantages of kernel-space execution while reducing the amount of memory individual drivers can access. Early prot