Post #2187633
2026-05-07 20:07 UTC
Oh FFS.
#DirtyFrag
https://github.com/V4bel/dirtyfrag/blob/master/assets/write-up.md
"Because the embargo has now been broken, no patches or CVEs exist for these vulnerabilities."
https://www.openwall.com/lists/oss-security/2026/05/07/8
Well, just put that CopyFail incident work on rinse and repeat, I suppose...
Replies (4)
-
@jrp@hub.kliklak.net 2026-05-07 20:25
@@jschauma@mstdn.social Now we're talkin'.
-
@bob_zim@infosec.exchange 2026-05-07 21:12
@jschauma@mstdn.social At least it was released with a known mitigation. No idea offhand what the esp4, esp6, and rxrpc modules are used for, though. Edit: esp4 is IPSec for IPv4, esp6 is IPSec for IPv6, and rxrpc is both a reliability layer which runs over UDP and an RPC system which runs over the reliability layer. I have a lot of IPSec VPNs, so can’t very well disable esp4 or esp6. Cool.
-
@codingpanic@mastodon.social 2026-05-07 23:29
@jschauma@mstdn.social at this point just unplug all the things.
-
@joany@mastodon.bsd.cafe 2026-05-08 12:56
@jschauma@mstdn.social Thank you man.. haha 😂