Hey, we have another linux kernel local root exploit in IPSEC. If you build your own kernels: you probably don't need ipsec, disable INET{6,}_{ESP,AH}.
Conversation
Notices
-
Embed this notice
hanno (hanno@mastodon.social)'s status on Thursday, 14-May-2026 04:58:52 JST
hanno
-
Embed this notice
Rich Felker (dalias@hachyderm.io)'s status on Thursday, 14-May-2026 05:03:58 JST
Rich Felker
@hanno Is there a full list of all the ipsec module names to drop in a file in /etc/modprobe.d/ to prevent any of them from getting loaded? On a distro-provided kernel that has everything modular that would be a complete in-advance fix for all the future vulns.
-
Embed this notice
hanno (hanno@mastodon.social)'s status on Thursday, 14-May-2026 21:07:07 JST
hanno
@dalias I think in both vulnerability cases it was in ESP (esp{4,6} modules for IPv4/v6). But AH is also "something from IPSEC", so I disabled that as well. I'm not super familiar with IPSEC beyond "it's something I do not use and do not need"...
-
Embed this notice
Rich Felker (dalias@hachyderm.io)'s status on Thursday, 14-May-2026 21:07:07 JST
Rich Felker
@hanno Yeah. I was asking for the full list including as-yet-unexploited modules.
-
Embed this notice