Post #2278242
2026-05-07 20:13 UTC
FFS again?? https://github.com/0xdeadbeefnetwork/Copy_Fail2-Electric_Boogaloo
If you have a modular kernel, blocking loading of modules esp4 and esp6 (IPsec 💩) in modprobe.d config should mitigate.
Given that this is the second time, a system-global seccomp filter blocking all splice-type syscalls/syscall-flags would probably be safer.
Replies (2)
-
@emma@orbital.horse 2026-05-07 20:16
@dalias@hachyderm.io okay, I'm not a kernel person, should we be applying the mitigation described here, or something similar? https://github.com/V4bel/dirtyfrag Or do I go back to MacOS until there's a fix?
-
@alwayscurious@infosec.exchange 2026-05-07 20:22
@dalias@hachyderm.io Is splice even useful nowadays?