A new GitHub project demonstrates how eBPF telemetry, module disarmament and user namespace hardening neutralize three CISA-tracked Linux kernel zero-days without any host reboots. The layered controls buy critical time until vendor patches arrive. Production operators now have concrete steps to close exposure immediately.