@hanno Is there a full list of all the ipsec module names to drop in a file in /etc/modprobe.d/ to prevent any of them from getting loaded? On a distro-provided kernel that has everything modular that would be a complete in-advance fix for all the future vulns.