3 ms·
The lesson here being... compile your own kernel from git sources every few days? Give up entirely on non-virtualized container security? This is not sarcasm.
by marshray 5mo ago
The lesson here being... compile your own kernel from git sources every few days?
Give up entirely on non-virtualized container security?
This is not sarcasm. I'd finally given in and started learning about docker/podman-style OCI containerization last week.
- john_strinlai 5mo agoin this specific case, they offer an alternative mitigation if your chosen distro has not updated yet: For immediate mitigation, block AF_ALG socket creation via seccomp or blacklist the algif_aead module: echo "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif-aead.conf rmmod algif_aead 2>/dev/null
- marshray 5mo agoThanks! I'd do 'umask 133' in front of the echo out of paranoia. Out of curiosity, was the asterisk after '2>/dev/null' intentional? I had not seen that idiom before.
- john_strinlai 5mo agothe asterisk is my oops, trying to format the comment in italics to differentiate my comment from the text provided by the author. sorry for the confusion
- ranger_danger 5mo agoAnd I would do chattr +i disable-algif.conf
- x4132 5mo agoare you sure containerization would be more secure? this is also a rootless podman escape. the lesson here is to not give random people shell access to your systems.
- marshray 5mo agoNo, I meant that I'd resisted doing anything with Docker for its entire existence and just finally gave in and started messing with podman. I have amazing timing.
- DooMMasteR 5mo agoI mean, most Kernel version literally got the patch 2026.04.30, so just today.