4 ms·
Sounds like this one is in the same kernel modules as dirtyfrag, so the existing mitigations (if in place) are sufficient.
by itintheory 5mo ago
Sounds like this one is in the same kernel modules as dirtyfrag, so the existing mitigations (if in place) are sufficient.
- chasil 5mo agoRedHat's mitigation is this: $ cat /etc/modprobe.d/dirtyfrag.conf install esp4 /bin/false install esp6 /bin/false install rxrpc /bin/false Are those correct for this exploit? https://access.redhat.com/security/vulnerabilities/RHSB-2026-003 https://access.redhat.com/security/vulnerabilities/RHSB-2026...
- LawnGnome 5mo agoI don't know, but the problem with blocking esp4 and esp6 is that IPsec stops working, as I understand it.
- cpach 5mo agoFor those who can I would recommend upgrading to Wireguard.
- itintheory 5mo agoYep, that's the advice from AWS for the previous set of vulnerabilities: https://aws.amazon.com/security/security-bulletins/2026-027-aws/ https://aws.amazon.com/security/security-bulletins/2026-027-... That one also includes disabling user namespaces. Could be problematic if they're in use.