3 ms·
RedHat's mitigation is this: $ cat /etc/modprobe.d/dirtyfrag.conf install esp4 /bin/false install esp6 /bin/false install rxrpc /bin/false Are those c
by chasil 5mo ago
RedHat's mitigation is this:
$ cat /etc/modprobe.d/dirtyfrag.conf
install esp4 /bin/false
install esp6 /bin/false
install rxrpc /bin/false
Are those correct for this exploit?
https://access.redhat.com/security/vulnerabilities/RHSB-2026-003 https://access.redhat.com/security/vulnerabilities/RHSB-2026...
- LawnGnome 5mo agoI don't know, but the problem with blocking esp4 and esp6 is that IPsec stops working, as I understand it.
- cpach 5mo agoFor those who can I would recommend upgrading to Wireguard.
- itintheory 5mo agoYep, that's the advice from AWS for the previous set of vulnerabilities: https://aws.amazon.com/security/security-bulletins/2026-027-aws/ https://aws.amazon.com/security/security-bulletins/2026-027-... That one also includes disabling user namespaces. Could be problematic if they're in use.