The file 'CANs.patch' is a patch for the Linux kernel v6.2.7, which implements the defense proposed in our paper [1].
Once this patch is integrated into the kernel, our defense solution will run automatically.
[1] Losing the Beat: Understanding and Mitigating Desynchronization Risks in Container Isolation, NDSS 2026