
For mitigating Spectre Variant Two and Spectre Variant Four (Speculative Store Bypass Disable - SSBD), SECCOMP threads see the mitigation by default while other threads rely on per-thread controls via prctl. Linux kernel developers from the likes of Red Hat and Google are now looking at not applying the mitigations by default to SECCOMP threads for the








