Kernel Mode
- In Turkish
- çekirdek kipi
- Pronunciation
- KUR-nul mohd
In short
Kernel mode is the privileged CPU state in which the OS kernel has full access to hardware and memory, while ordinary programs run in restricted user mode.
What is kernel mode?
Processors enforce privilege levels in hardware. On x86 they are called rings: the kernel runs in ring 0, with every instruction and all memory available, and applications run in ring 3, where instructions that touch hardware directly, change memory mappings or disable interrupts are forbidden. ARM has similar exception levels.
When a program needs something only the kernel may do, such as reading a file, allocating memory or sending a network packet, it makes a system call. The CPU switches into kernel mode, runs the kernel's handler, and switches back to user mode with the result. Interrupts and faults, such as a page fault, also enter kernel mode.
This separation is what keeps one crashing application from taking down the whole computer: user-mode programs can only damage themselves. Code that runs in kernel mode, including device drivers and some security software, has no such safety net. A bug there can crash the entire system, causing a Linux kernel panic or a Windows blue screen, as a faulty security update did on millions of Windows computers in 2024.
A common misconception is that switching to kernel mode is free. Each system call costs a mode switch, so programs that make huge numbers of tiny calls can be slow, which is why I/O libraries buffer data and why newer interfaces such as Linux's io_uring batch many operations into fewer transitions.
Key takeaways
- Kernel mode gives the OS kernel full access to hardware and memory.
- Applications run in restricted user mode.
- System calls, interrupts and faults switch the CPU into kernel mode.
- Bugs in kernel-mode code, such as drivers, can crash the whole system.
- Mode switches cost time, so I/O is buffered and batched.
Readers ask
What is the difference between kernel mode and user mode?
In kernel mode, code can execute any instruction and access any memory or device. In user mode, code is restricted to its own memory and must request privileged operations from the kernel through system calls.
Why do device drivers run in kernel mode?
Drivers talk directly to hardware and handle interrupts, which needs privileged access. That is also why a buggy driver can crash the whole operating system, and why some systems move drivers into user space where possible.
What are protection rings?
Hardware privilege levels on x86 processors, numbered from 0, the most privileged, to 3, the least. Operating systems typically use only ring 0 for the kernel and ring 3 for applications.
See also
- KernelOperating Systems, p. 17A kernel is the core part of an operating system that manages the CPU, memory, and hardware devices and controls how programs get access to those resources.
- User SpaceOperating Systems, p. 36User space is the restricted area where ordinary programs run, kept separate from kernel space so a buggy or malicious app cannot take down the whole system.
- System CallOperating Systems, p. 31A system call is a request from a program to the operating system kernel to perform a privileged action, such as reading a file or starting a process.
- InterruptOperating Systems, p. 16An interrupt is a signal to the CPU that an event needs immediate attention, making it pause its current work and run a special handler in the kernel.
- Device DriverOperating Systems, p. 9A device driver is software that lets the operating system control a specific piece of hardware, translating generic OS requests into device-specific commands.
- Operating SystemOperating Systems, p. 21An operating system (OS) is the core software that manages a computer's hardware, shares it out among programs and gives them a common way to use it.
Spotted a mistake or something missing on this page?Suggest an edit